Audit Monitoring - Domain Controller

karthik palani 1,036 Reputation points
2020-09-17T13:33:30.17+00:00

Hi All,

I have 8 domain controllers and some of the admins have RSAT - Remote server administration tool locally installed on Windows 10 machines.

For resetting the password or any other activity they do it locally which is not getting logged in domain controller audit security event. Is there a way we can monitor this RSAT activity. Please suggest

Windows Server
Windows Server
A family of Microsoft server operating systems that support enterprise-level management, data storage, applications, and communications.
12,859 questions
Active Directory
Active Directory
A set of directory-based technologies included in Windows Server.
6,382 questions
0 comments No comments
{count} votes

3 answers

Sort by: Most helpful
  1. Lucas 16 Reputation points
    2020-09-18T20:59:34.617+00:00

    You can create a group policy targeting your domain controllers to enable Security Audit, specifically "Audit account management", you can find the documentation about these events here: https://video2.skills-academy.com/en-us/windows/security/threat-protection/auditing/basic-audit-account-management

    So, you need to configure auditing under Computer Configuration\Windows Settings\Security Settings\Local Policies\Audit Policy.

    1 person found this answer helpful.
    0 comments No comments

  2. karthik palani 1,036 Reputation points
    2020-09-20T07:12:29.977+00:00

    Yes we tried this option but still the local computer audit information is not stored in the domain controller.

    Only changes on Domain Controller is getting stored. Please let me know if there is any other way we can monitor this

    0 comments No comments

  3. Fan Fan 15,326 Reputation points Microsoft Vendor
    2020-09-23T02:09:56.02+00:00

    Hi,
    Based on my understanding, even the changes were made from the workstation ,the events for the account management should be also logged on the DCs.
    Even we manage the accounts from the workstations, the opteration should by done by connect to the DCs.

    I also did a test : i try to change password and create new user accounts through RSAT from the workstation, the management events were logged on the DCs.

    So i would recommend you check if the the audit policy was on the DCs by :

    Configure the settings to success and failure through the Advanced Audit Policy.
    26569-9236.jpg
    Then run gpupdate /force on the DC and run command :gpresult /h to confirm if the policy was applied successfully.


Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.