none
Windows security auditing

    Question

  • We have server 2012 R2 Active Directory. We are running Exchange 2013, latest RU. We have audit enabled within GPO. Testing this audit, I made a change to an AD User Object from ADUC by making a change to the Display Name. That change was reported as a 5136 Event ID in the Security Log of the Domain Controller that ADUC was attached to.

    I used ECP to edit the same user object by making a change to the Display Name. That event was not recorded in any event log on any of the servers within the environment.

    Am I looking in the wrong log or is there some other audit setup I must use to audit changes to objects when they are change in ECP?

    Thanks,

    Don

    Wednesday, November 09, 2016 6:04 PM

All replies