I have created an alert if anyone changed the group type in AD.
I can see the group name and change type in the event which is being triggered.
Can you please let me know what are the important checks that we need to check in the event?
What we have to check in the change type?
Sometime, the alert will be triggered when the change from security disabled group to enabled group.
What are the abnormal activity with respective to this event?
Thanks & Regards,
Sundar