﻿<?xml version='1.0' encoding='UTF-8'?><rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/"><channel><title>UltimateWindowsSecurity.com Forum / Ultimate Windows Security Forum / IT Audit / Active Directory </title><generator>InstantForum.NET v4.1.4</generator><description>UltimateWindowsSecurity.com Forum</description><link>http://forum.ultimatewindowssecurity.com/</link><webMaster>noreply@ultimatewindowssecurity.com</webMaster><lastBuildDate>Tue, 07 Feb 2012 11:49:43 GMT</lastBuildDate><ttl>20</ttl><item><title>Event ID 566</title><link>http://forum.ultimatewindowssecurity.com/Topic898-8-1.aspx</link><description>I'm getting event ID 566 success after moving a user account into a security group. Windows 2003. Can anyone advise why I am getting this please? I am unaware of any other changes being made.</description><pubDate>Thu, 26 Jan 2012 17:26:36 GMT</pubDate><dc:creator>Ronnie</dc:creator></item><item><title>AD Upgrade from 2003 to 2008 R2</title><link>http://forum.ultimatewindowssecurity.com/Topic803-8-1.aspx</link><description>Can someone provide points to be check as an IT auditor involved in AD upgrade to 2008 R2?</description><pubDate>Sun, 18 Sep 2011 09:02:09 GMT</pubDate><dc:creator>ochoksy</dc:creator></item><item><title>SIEM Vendor Matrix</title><link>http://forum.ultimatewindowssecurity.com/Topic432-8-1.aspx</link><description>Hello all&lt;P&gt;&lt;BR&gt;This post is not inteded to only focus on AD Audits, but I didn't see a forum for more generalized IT Audits.  Does anyone have any suggestions a good comprehensive source comparing features of various SIEM vendors/products?  Just looking to avoid recreating the wheel, if there is already a good source of information out there.  Features like...  agents - required, optional, or do not exist...  sources - what sources can the system collect information from?...   native auditing - does the system only use native Microsoft auditing, or does the agent add functionality?   scalability, archiving?, throughput (EPS), and possibly even cost/licensing.&lt;/P&gt;&lt;P&gt;Vendors/Products that come to mind (in no particular order):&lt;/P&gt;&lt;P&gt;     Microsoft - Audit Collection Services (ACS/SCOM)&lt;/P&gt;&lt;P&gt;     Quest - Change Auditor&lt;/P&gt;&lt;P&gt;     Quest - InTrust&lt;/P&gt;&lt;P&gt;     Prism Microsystems - Event Tracker&lt;/P&gt;&lt;P&gt;     Tripwire - LogCenter&lt;/P&gt;&lt;P&gt;     Tripwire - Enterprise&lt;/P&gt;&lt;P&gt;     ArcSight - ESM&lt;/P&gt;&lt;P&gt;     Splunk - Enterprise&lt;/P&gt;&lt;P&gt;Any information or even opinions on various products would be very much appreciated!  I realize that not all of these products technically fall into a "SIEM" solution, but most can acomplish similar goals to different scales.  &lt;/P&gt;&lt;P&gt;Thanks for any feedback!&lt;/P&gt;&lt;P&gt;Steve</description><pubDate>Thu, 26 Aug 2010 14:42:40 GMT</pubDate><dc:creator>sgrinker</dc:creator></item><item><title>Detecting Concurrent Logins</title><link>http://forum.ultimatewindowssecurity.com/Topic704-8-1.aspx</link><description>I want to detect concurrent user logins within the domain. Audit log policy is implemented and workstation logs are saved on the AD. I examined the audit logs and Event ID 528 and 672 looks promising. However, I am not sure how can I detect concurrent logins through any of these events. Any help in this regard will be greatly appreciated.</description><pubDate>Thu, 02 Jun 2011 03:26:55 GMT</pubDate><dc:creator>darknight007</dc:creator></item><item><title>AD accounts</title><link>http://forum.ultimatewindowssecurity.com/Topic691-8-1.aspx</link><description>What is the difference between disableing and expiring an active directory user account when an employee is terminated? Our auditor says we have to disable it.</description><pubDate>Fri, 13 May 2011 13:50:09 GMT</pubDate><dc:creator>tommymilos</dc:creator></item><item><title>is it possible for a deleted domain account to log into a domain workstation?</title><link>http://forum.ultimatewindowssecurity.com/Topic627-8-1.aspx</link><description>I use to monitor the event logs of the directive board of the company every two months, yersterday i came across with an account of an user that even past away, apart from not working in the company any loger... and the account registered a successful network logon into another computer... any clues?</description><pubDate>Wed, 30 Mar 2011 13:53:42 GMT</pubDate><dc:creator>pnova</dc:creator></item><item><title>Map IP address to domain credential supplied</title><link>http://forum.ultimatewindowssecurity.com/Topic608-8-1.aspx</link><description>I am trying to figure out the best tool to extract domain logins from our domain controllers, such that I can create a network map that shows every credential used by any given IP address in our network. What would be the best tool to accomplish this task?</description><pubDate>Thu, 24 Feb 2011 16:16:45 GMT</pubDate><dc:creator>ddrumm</dc:creator></item><item><title>Expired accouts</title><link>http://forum.ultimatewindowssecurity.com/Topic599-8-1.aspx</link><description>In AD users and computers, when a user account was disabled, a red x is shown on the account. But how to identify an expired account or to know it's actually expired? When right click on the account supposed to be expired, the Disable Account option is available. Does that mean that an account can be expired but not disabled? Thanks in advance for all the helps.</description><pubDate>Thu, 17 Feb 2011 11:01:26 GMT</pubDate><dc:creator>yuanqian</dc:creator></item><item><title>ADCS audit</title><link>http://forum.ultimatewindowssecurity.com/Topic591-8-1.aspx</link><description>Has anyone done a AD certificate services audit or review? I would like to have some insights and suggestions. Thanks.</description><pubDate>Thu, 10 Feb 2011 15:03:39 GMT</pubDate><dc:creator>yuanqian</dc:creator></item><item><title>How to create "restricted access" in AD</title><link>http://forum.ultimatewindowssecurity.com/Topic575-8-1.aspx</link><description>AD authenticates all users and groups reside in all domains in the forest. Is there a feature in AD to disallow a particular group or user from accessing another domain? Or should this be done using network features?</description><pubDate>Mon, 07 Feb 2011 09:40:19 GMT</pubDate><dc:creator>yuanqian</dc:creator></item><item><title>Logging computer moves between OU's</title><link>http://forum.ultimatewindowssecurity.com/Topic174-8-1.aspx</link><description>What auditing events or other dependencies must be enabled to record these issues:&lt;/P&gt;&lt;P&gt;1.  when a computer account is moved between OU's?  &lt;/P&gt;&lt;P&gt;2.  when GPO's are applied or removed from computer accounts</description><pubDate>Thu, 13 Aug 2009 15:31:38 GMT</pubDate><dc:creator>des2009</dc:creator></item><item><title>AZMAN (Authorization Manager) Events</title><link>http://forum.ultimatewindowssecurity.com/Topic137-8-1.aspx</link><description>Hi, &lt;/P&gt;&lt;P&gt;I'd loke to know how to implement Azman Audit. I recently enable the audit in Authorization manager, but I didn't receive any event in the security Log.&lt;/P&gt;&lt;P&gt;I also check that "Directory Service Access" is enabled in AD as Microsoft recommends, but nothing happens.&lt;/P&gt;&lt;P&gt;Any Idea?&lt;/P&gt;&lt;P&gt;Thanks.</description><pubDate>Mon, 20 Jul 2009 14:26:28 GMT</pubDate><dc:creator>pstamati</dc:creator></item><item><title>Restrict user logins to 1 simultaneous/concurrent login</title><link>http://forum.ultimatewindowssecurity.com/Topic428-8-1.aspx</link><description>I am trying to figure out how to restrict user logins to 1 concurrent session in our environment. So far, no luck from technet posts to do it natively - turning a switch, GPO. Saw reference to limitlogin (doesn't seem to work in 2008R2 environment) and 3rd party tool UserLock. Trying my luck in this post for any recommendation/advice.&lt;br&gt;&lt;br&gt;Cheers,&lt;br&gt;Oliver</description><pubDate>Sun, 22 Aug 2010 01:39:18 GMT</pubDate><dc:creator>oliverc</dc:creator></item><item><title>Auditing for account or group creation priviledge</title><link>http://forum.ultimatewindowssecurity.com/Topic396-8-1.aspx</link><description>How can a user or group access privilege escalation for account or group&lt;br&gt;creation can be audited and reported with the Windows 2003 active directory.&lt;br&gt;&lt;br&gt;Even with all auditing enabled It only shows event id 566 as the only&lt;br&gt;significant event with little info as below. It doesn't display the user or&lt;br&gt;group being granted acccess for and/or access to&lt;br&gt;&lt;br&gt;Accesses: WRITE_DAC&lt;br&gt;&lt;br&gt;Properties:&lt;br&gt;WRITE_DAC&lt;br&gt;&lt;br&gt;Also, in the Webnar "Top 10 Active Directory Changes to Monitor in the Security Log" it is mentioned in the slide for event 565 while it actual is event 566 as shown in the example as well.&lt;br&gt;&lt;br&gt;Thanks &lt;br&gt;Sunil Gupta</description><pubDate>Mon, 28 Jun 2010 09:31:57 GMT</pubDate><dc:creator>SGupta</dc:creator></item><item><title>Auditing Password Length</title><link>http://forum.ultimatewindowssecurity.com/Topic399-8-1.aspx</link><description>We require that Windows/Active Directory passwords for certain sensitive accounts be a minimum length of 15 characters.  &lt;P&gt;&lt;FONT size=2&gt;I've noticed that L0phtcrack is able to very rapidly detect when an account's password is greater than 14 characters.  Are there any other tools that can do that quickly and, preferably, be automated to scan through entire forests?  Any that can report actual length?&lt;/FONT&gt;</description><pubDate>Thu, 01 Jul 2010 10:22:27 GMT</pubDate><dc:creator>jlashnits</dc:creator></item><item><title>Privileged access</title><link>http://forum.ultimatewindowssecurity.com/Topic335-8-1.aspx</link><description>What logged events could be used to indicate that a new Active Directory group has been added that has Domain Admin equivalent access?  In theory, a group could be added that's called "Inquiry" and is given Full Control to everything in the domain - is there a logged event or series of logged events that could identify this activity?  Certainly the naming convention is not useful in this example...</description><pubDate>Tue, 16 Mar 2010 11:18:07 GMT</pubDate><dc:creator>kkscfb</dc:creator></item><item><title>Audit Windows 2008 File Shares</title><link>http://forum.ultimatewindowssecurity.com/Topic321-8-1.aspx</link><description>I have a 3 node Windows 2008 cluster that has most of our file shares. Someone is making changes to share\folder\file permissions that is causeing me a lot of problems. I am trying to figure out the best way to audit who is making the changes.&lt;/P&gt;&lt;P&gt;I have SCOM 2007 R2 in my environment, so I can also utilize that to report on who is making changes.&lt;/P&gt;&lt;P&gt;Please help!!!</description><pubDate>Sat, 27 Feb 2010 18:55:57 GMT</pubDate><dc:creator>dvdkea</dc:creator></item><item><title>Event ID for modified GPOs</title><link>http://forum.ultimatewindowssecurity.com/Topic315-8-1.aspx</link><description>I have to know, who (usersid or loginname) changed a specified GPO for a specified OU in the Active Directory. Given our audit settings include this, what would be the right Event ID to look for?</description><pubDate>Mon, 22 Feb 2010 04:16:19 GMT</pubDate><dc:creator>hinek</dc:creator></item><item><title>Difference between Admin group and domain admin group in AD</title><link>http://forum.ultimatewindowssecurity.com/Topic292-8-1.aspx</link><description>Can anyone describe the difference between the AD groups admin and domain admin?  Can the AD admin group do just as much, security wise, as the domain admin group?</description><pubDate>Tue, 29 Dec 2009 12:26:33 GMT</pubDate><dc:creator>duketter</dc:creator></item></channel></rss>
