Info about Event logs (Active directory)

Ramanjaneyulu Butharaju 421 Reputation points
2020-08-25T07:42:07.46+00:00

Recently 3 of my Active directory admins are unable to login to AD server through RDP.

After we cross checked everything, we found these 3 users are added in one security group called "Deny RDP access" after i removed users from this group they are able to login now.

I just want to check is there any logs that can give me information about who added these 3 users into this "Deny RDP access" group ?

Is this security group(Deny RDP Access) is default or created one ??

If its created one, how to check who created it ?

Thanks,
Ram

Windows Server 2016
Windows Server 2016
A Microsoft server operating system that supports enterprise-level management updated to data storage.
2,425 questions
Windows Server 2012
Windows Server 2012
A Microsoft server operating system that supports enterprise-level management, data storage, applications, and communications.
1,564 questions
Windows Server
Windows Server
A family of Microsoft server operating systems that support enterprise-level management, data storage, applications, and communications.
12,525 questions
Remote Desktop
Remote Desktop
A Microsoft app that connects remotely to computers and to virtual apps and desktops.
4,369 questions
0 comments No comments
{count} votes

Accepted answer
  1. Hannah Xiong 6,256 Reputation points
    2020-08-25T09:40:03.317+00:00

    Hello,

    Thank you so much for posting here.

    To check the logs of new created security group and the member is added to this group and who creates this group, we could configure the below audit policy.

    20231-1.png

    And then check the Event Viewer to check the security events as shown below.

    20214-2.png

    20241-3.png

    Reference: https://video2.skills-academy.com/en-us/windows/security/threat-protection/auditing/audit-security-group-management

    As per my research, this security group (Deny RDP Access) should be created one since I did not find this group in my AD environment. If it is created one, there might be other configuration of deny log on through RDS, such as this group policy setting as shown below. We could kindly have a check whether this policy is configured or not.

    Computer configuration\Policies\Windows Settings\Security Settings\Local Policies\User Rights Assignment

    20119-4.png

    For any question, please feel free to contact us.

    Best regards,
    Hannah Xiong

    0 comments No comments

2 additional answers

Sort by: Most helpful
  1. Ramanjaneyulu Butharaju 421 Reputation points
    2020-08-26T14:06:40.287+00:00

    HannahXiong-MSFT,

    Thank you so much. i will check your suggestions and get back to you.


  2. Ramanjaneyulu Butharaju 421 Reputation points
    2020-09-03T06:19:42.48+00:00

    hannahxiong,

    Unfortunately,
    Didn't find any event logs.

    anyways thanks. I learn some new things here..