active-directory – 已修改GPO的事件ID

我必须知道,谁(usersid或loginname)更改了Active Directory中指定OU的指定GPO.鉴于我们的审计设置包含此项,要查找的事件ID是什么?
Windows Server 2008上,它是事件ID 5136( Directory Service Changes).另请参见事件ID 5137(创建),5138(取消删除),5130(移动).事件ID 4662包含旧式审核事件(见下文).

在Windows 2000 Server和Windows Server 2003上:

[T]he policy Audit directory service access was the only auditing control available for Active Directory. The events that were generated by this control did not show the old and new values of any modifications. This setting generated audit events in the Security log with the ID number 566. In Windows Server 2008,the audit policy subcategory Directory Service Access still generates the same events,but the event ID number is changed to 4662.

相关文章

文章浏览阅读2.2k次,点赞6次,收藏20次。在我们平时办公工作...
文章浏览阅读1k次。解决 Windows make command not found 和...
文章浏览阅读3.2k次,点赞2次,收藏6次。2、鼠标依次点击“计...
文章浏览阅读1.3w次。蓝光版属于高清版的一种。BD英文全名是...
文章浏览阅读974次,点赞7次,收藏8次。提供了更强大的功能,...
文章浏览阅读1.4w次,点赞5次,收藏22次。如果使用iterator的...