How to Audit Active Directory Changes using Event Logs

To track changes in Active Directory, you first need to enable Active Directory auditing through Group Policy and configure auditing for the AD objects or containers you want to monitor. You can then review Active Directory audit logs in the Security log on your domain controllers to find out who made a change, what was changed, and when it occurred.

Directory Service Changes events (5136–5141) record changes such as AD objects being created, modified, moved, restored, or deleted, while Account Management events (47xx) record activities such as user account and security group changes.

This article explains how to enable AD auditing using Group Policy Management Console (GPMC), configure object-level auditing using ADSI Edit, and review AD audit logs using Event Viewer and relevant Windows Security event IDs. It also explains how Lepide can simplify Active Directory change auditing with centralized monitoring, reporting, and alerting.

How to Enable Active Directory Auditing Using Group Policy

Please follow the steps:

  1. Sign in to a domain controller with appropriate administrative privileges. Open Server ManagerToolsGroup Policy Management.
  2. In the Group Policy Management Console, expand ForestDomainsYour DomainDomain Controllers. Right-click Default Domain Controllers Policy and select Edit. Alternatively, you can edit a dedicated GPO linked to the Domain Controllers OU.
  3. In the Group Policy Management Editor, navigate to:
    Computer ConfigurationPoliciesWindows SettingsSecurity SettingsAdvanced Audit Policy ConfigurationAudit Policies navigate to audit policies
  4. Expand DS Access, double-click Audit Directory Service Changes, select Configure the following audit events, enable Success, and click OK. Configure events in DS Access
  5. Expand Account Management and configure the following audit subcategories:
    • Audit User Account Management – Enable Success and Failure.
    • Audit Computer Account Management – Enable Success and Failure.
    • Audit Security Group Management – Enable Success and Failure.enable account management events
  6. Close the Group Policy Management Editor. The updated policy will be applied during the normal Group Policy refresh cycle. To apply the policy immediately on a domain controller, open Command Prompt as an administrator and run:
    gpupdate /force

Configure Active Directory Object Auditing Using ADSI Edit

After enabling Audit Directory Service Changes in Group Policy, configure auditing on the Active Directory objects or containers whose changes you want to track.

  1. Sign in to a domain controller with appropriate administrative privileges. Press Windows + R, type adsiedit.msc, and press Enter.
  2. In ADSI Edit, right-click ADSI Edit and select Connect to.
  3. Under Select a well known Naming Context, select Default naming context, and click OK.
  4. Expand the Default naming context and locate the domain, organizational unit (OU), or container that you want to audit.
  5. Right-click the object or container and select Properties.
  6. Select the Security tab, click Advanced, and then select the Auditing tab.
  7. Click Add, and then click Select a principal. Specify the users or groups whose changes you want to audit. To audit changes made by all users, select Everyone.
  8. Set Type to Success and choose the appropriate option under Applies to. If you are configuring auditing on an OU or container, select the appropriate descendant scope if you also want to audit changes to objects beneath it.
  9. Under Permissions, select the operations you want to audit, such as creating or deleting objects, writing properties, or modifying permissions. ADSI Edit
  10. Click OK to save the auditing entry, and then click OK again to close the Advanced Security Settings and Properties windows.

How to Review Active Directory Audit Logs in Event Viewer

After configuring the required audit policies and object auditing, you can review Active Directory changes in the Security log on a domain controller.

  1. Open Server ManagerToolsEvent Viewer.
  2. Navigate to Windows LogsSecurity.
  3. Click Filter Current Log in the Actions pane.
  4. In the <All Event IDs> field, enter the event IDs for the types of Active Directory changes you want to investigate. Search Event IDs

    Directory Service Changes

    Event ID Description
    5136 A directory service object was modified
    5137 A directory service object was created
    5138 A directory service object was undeleted
    5139 A directory service object was moved
    5141 A directory service object was deleted

    User Account Changes

    Event ID Description
    4720 A user account was created
    4722 A user account was enabled
    4723 An attempt was made to change an account’s password
    4724 An attempt was made to reset an account’s password
    4725 A user account was disabled
    4726 A user account was deleted
    4738 A user account was changed
    4740 A user account was locked out

    Security Group Membership Changes

    Event ID Description
    4728 A member was added to a security-enabled global group
    4729 A member was removed from a security-enabled global group
    4732 A member was added to a security-enabled local group
    4733 A member was removed from a security-enabled local group
    4756 A member was added to a security-enabled universal group
    4757 A member was removed from a security-enabled universal group
  5. Click OK to display the matching events.
  6. Open an event and review its details to determine who performed the action, which account or Active Directory object was affected, when the change occurred, and other information associated with the event. Event ID 5136 details

For Event ID 5136, review fields such as Subject, Object, Attribute LDAP Display Name, Attribute Value, and Operation Type. An attribute modification can generate separate events showing Value Deleted for the previous value and Value Added for the new value.

How Lepide Active Directory Auditor Tracks Changes Made in AD

For many users, manual auditing can be both time-consuming and unreliable, as you have to search lots of audit logs in the Event Viewer; it does not generate instant alerts and reports for Active Directory changes.

It is therefore recommended that you opt for an automated Active Directory auditing solution. One such solution is Lepide Active Directory Auditor, which enables users to pro-actively track, alert and report on changes being made to Active Directory.

Lepide’s Active Directory audit solution for records the details of every change made in the configuration of Active Directory and generates 90 reports in three different categories – Active Directory Modification Reports, Active Directory Security Reports, and Active Directory State Reports.

Below are some screenshots that show how our Active Directory auditing solution helps IT administrators track changes in Active Directory objects. Three reports are shown below; a report for objects created, objects deleted and objects modified.

  1. Object Created Report

Object Created Report - screenshot

  1. Object Deleted Report

Object Deleted Report - screenshot

  1. Object Modifications Report

Object Modifications Report - screenshot
You can also track other activities like successful and failed logon attempts, account lockouts, permissions changes, privilege user activities etc. easily with our solution.

The Final Note

Lepide Active Directory Auditor for can actually make the whole Active Directory auditing process simpler through its intuitive user interface and sending real-time alerts as emails to desired recipients, as updates to LiveFeed widget, and as push-notifications to Lepide Mobile App to ensure the security of your Active Directory environment.

Audit AD changes in real time with Lepide Active Directory Auditor
Fill in the rest of the form to
Get access to Lepide now
x