locked
Task Scheduler - audit RRS feed

  • Question

  • Hello!

    There is a scheduled task running under specific account. Every administrator can run this job on demand. How can we identify who started the task?
    There are many operational and audit events for task scheduler, but they don't contain information about initiator.
    https://technet.microsoft.com/en-us/library/dd363625(v=ws.10).aspx
    https://technet.microsoft.com/en-us/library/dn319119.aspx
    Audit Object Access Events can help in this case, but I can't find universal event id, because administrator can start task using various methods, such as mmc, schtasks, powershell cmdlets, etc...
    Does anybody know a method for that?

    Thank you.

    Да я просто почитать зашел :-)

    Friday, February 12, 2016 8:34 PM

Answers

All replies