Directory Service Event: 566

Active Directory Auditing Tool

The Who, Where and When information is very important for an administrator to have complete knowledge of all activities that occur on their Active Directory. This helps them identify any desired / undesired activity happening. ADAudit Plus assists an administrator with this information in the form of reports. In real-time, ensure critical resources in the network like the Domain Controllers are audited, monitored and reported with the entire information on AD objects - Users, Groups, GPO, Computer, OU, DNS, AD Schema and Configuration changes with 200+ detailed event specific GUI reports and email alerts.

System Event » Directory Service Event: 566

Event ID 566: Object Operation (W3 Active Directory).

Description This event logs the permissions actually exercised by the user/program after opening the object in event 565
Category Directory service

This event logs the following information:

Object
  • Object Server
  • Object type
  • Object name
Operation type
  • -
Handle ID -
Primary user
  • Primary user name
  • Primary Domain
  • Primary logon ID
Client user
  • Client user name
  • Client domain
  • Client logon ID
Accesses
  • -
Properties -
Access mask -

Related events:

This event is similar to 567 but is limited to Active Directory object accesses.

Pro tip:

ADAudit Plus logs this event since it keeps track of every directory service object access. Eg. OU, GPO, container, contact and other object types besides security principals.

Event 565 applies to the following operating systems:

  • Windows Server 2003 and XP

Corresponding event in 2008 and above: Event 4662,5137