How To Detect Who Added A User To The Domain Admins Group
Maybe your like
Steps to enable auditing using the Group Policy Management Console (GPMC):
Perform the following actions on the domain controller (DC):
- Press Start, then search for and open the Group Policy Management Console, or run the command gpmc.msc.
- Right-click the domain or organizational unit (OU) that you want to audit, and click Create a GPO in this domain, and Link it here... If you have already created a Group Policy Object (GPO), go to step 4.
- Name the GPO.
- Right-click the GPO, and choose Edit.
- In the left pane of the Group Policy Management Editor, navigate to Computer Configuration → Policies → Windows Settings → Security Settings → Local Policies → Audit Policy.
- In the right pane, you will see a list of policies under Audit Policy. Double-click Audit account management, and check the boxes next to Define these policy settings, Success, and Failure.
- Click Apply, then OK.
- Go back to the Group Policy Management Console, and in the left pane, right-click the desired OU in which the GPO was linked, and click Group Policy Update. This step makes sure the new Group Policy settings are applied instantly instead of waiting for the next scheduled refresh.
Once this policy is enabled, whenever a user is added to the security-enabled group, corresponding events are logged under the DC's security log category.
Steps to view these events using Event Viewer
Once the above steps are complete, events will be stored in the event log. This can be viewed in the Event Viewer by following the steps below:
- Press Start, search for Event Viewer, and click to open it.
- In the left pane of the Event Viewer window, navigate to Windows Logs → Security.
- Here, you will find a list of all the security events that are logged in the system.
- In the right pane, under Security, click Filter Current Log.
- In the pop-up window, enter 4728 in the field labeled <All Event IDs>.
- Click OK. This will provide a list of occurrences of Event ID 4728, which is logged when a new user is added to a security group.
- Double-click the Event ID to view its properties (description). Look for Domain Admins under Group Name in the description.
The section labeled Subject shows who added the new user. The section labeled Member shows the name and SID of the new user that was added to the group.
This method is exhausting since you have to view each event's description to find the one that pertains to the Domain Admins group.
ADAudit Plus, a streamlined AD auditing tool, enables admins to effortlessly audit security group membership changes and other group management information.
Download 30-day, free trialTag » Active Directory Add User To Admin Group
-
Create A Domain Admin - Parallel Data Warehouse - Microsoft Docs
-
Adding Domain Users To The Local Administrators Group In Windows
-
Adding Domain Users To The Local Administrators Group Using ...
-
Add A User To The Local Administrators Group In Windows Server 2012
-
Add An Active Directory User To The Local Administrators Group Using ...
-
Add Service User To Local Administrators Group Via Group Policy
-
Assigning An Active Directory User With Administrator Rights
-
How To Add A Domain User To Administrators Group In Windows 10
-
How To Add Local Administrators Via GPO (Group Policy)
-
Windows Server 2016/2019 - Adding Domain Users To The Local ...
-
How To Add Users To The Local Admin Group - Bobcares
-
Configuring Permissions And Groups (Windows Server Domain ... - IBM
-
How To Add A Group To Local Administrators Via Group Policy
-
How To Make A Domain User The Local Administrator For All PCs