微信公众号搜"智元新知"关注
微信扫一扫可直接关注哦!

active-directory – 已修改GPO的事件ID

我必须知道,谁(usersid或loginname)更改了Active Directory中指定OU的指定GPO.鉴于我们的审计设置包含此项,要查找的事件ID是什么?
Windows Server 2008上,它是事件ID 5136( Directory Service Changes).另请参见事件ID 5137(创建),5138(取消删除),5130(移动).事件ID 4662包含旧式审核事件(见下文).

在Windows 2000 Server和Windows Server 2003上:

[T]he policy Audit directory service access was the only auditing control available for Active Directory. The events that were generated by this control did not show the old and new values of any modifications. This setting generated audit events in the Security log with the ID number 566. In Windows Server 2008,the audit policy subcategory Directory Service Access still generates the same events,but the event ID number is changed to 4662.

原文地址:https://www.jb51.cc/windows/367433.html

版权声明:本文内容由互联网用户自发贡献,该文观点与技术仅代表作者本人。本站仅提供信息存储空间服务,不拥有所有权,不承担相关法律责任。如发现本站有涉嫌侵权/违法违规的内容, 请发送邮件至 dio@foxmail.com 举报,一经查实,本站将立刻删除。

相关推荐