How to Audit Active Directory Changes using Event Logs

| Updated On - September 7, 2026

Active Directory changes such as user account modifications, group membership changes, computer account changes, and changes to directory objects can be recorded in the Security logs on domain controllers when the appropriate auditing is configured.

You can use Windows Event Viewer to find these events and determine who made a change, what object was affected, when the change occurred, and, for certain directory service changes, which attribute was modified.

This guide explains how to track Active Directory changes using Event Viewer and relevant Windows Security event IDs, including Directory Service Changes events (5136–5141) and Account Management events (47xx).

Prerequisites

Before tracking Active Directory changes, make sure:

  • The appropriate Advanced Audit Policy settings are enabled on your domain controllers.
  • You have permission to access the Security logs on your domain controllers.
  • Appropriate object-level auditing (SACLs) is configured where required for Directory Service Changes events.

Enable Auditing Before Tracking Active Directory Changes

Before Windows can record the required Active Directory changes, the appropriate Advanced Audit Policy settings must be enabled on your domain controllers.

In Group Policy Management, these settings are available under:
Computer ConfigurationPoliciesWindows SettingsSecurity SettingsAdvanced Audit Policy ConfigurationAudit Policies

For tracking common Active Directory changes, relevant audit subcategories include:

  • Audit Directory Service Changes – records changes to Active Directory objects.
  • Audit User Account Management – records user account management activities.
  • Audit Security Group Management – records changes to security groups and their membership.
  • Audit Computer Account Management – records computer account management activities.

Detailed Directory Service Changes events may also depend on appropriate object-level auditing entries (SACLs) being configured for the objects or containers you want to monitor.

For complete step-by-step instructions on configuring these audit policies and object-level auditing, see How to Enable Active Directory Auditing.

How to Review Active Directory Audit Logs in Event Viewer

After configuring the required audit policies and object auditing, you can review Active Directory changes in the Security log on a domain controller.

  1. Open Server ManagerToolsEvent Viewer.
  2. Navigate to Windows LogsSecurity.
  3. Click Filter Current Log in the Actions pane.
  4. In the <All Event IDs> field, enter the event IDs for the types of Active Directory changes you want to investigate. Search Event IDs

    Directory Service Changes

    Event ID Description
    5136 A directory service object was modified
    5137 A directory service object was created
    5138 A directory service object was undeleted
    5139 A directory service object was moved
    5141 A directory service object was deleted

    User Account Changes

    Event ID Description
    4720 A user account was created
    4722 A user account was enabled
    4723 An attempt was made to change an account’s password
    4724 An attempt was made to reset an account’s password
    4725 A user account was disabled
    4726 A user account was deleted
    4738 A user account was changed
    4740 A user account was locked out

    Security Group Membership Changes

    Event ID Description
    4728 A member was added to a security-enabled global group
    4729 A member was removed from a security-enabled global group
    4732 A member was added to a security-enabled local group
    4733 A member was removed from a security-enabled local group
    4756 A member was added to a security-enabled universal group
    4757 A member was removed from a security-enabled universal group
  5. Click OK to display the matching events.
  6. Open an event and review its details to determine who performed the action, which account or Active Directory object was affected, when the change occurred, and other information associated with the event. Event ID 5136 details

For Event ID 5136, review fields such as Subject, Object, Attribute LDAP Display Name, Attribute Value, and Operation Type. An attribute modification can generate separate events showing Value Deleted for the previous value and Value Added for the new value.

How Lepide Active Directory Auditor Tracks Changes Made in AD

For many users, manual auditing can be both time-consuming and unreliable, as you have to search lots of audit logs in the Event Viewer; it does not generate instant alerts and reports for Active Directory changes.

It is therefore recommended that you opt for an automated Active Directory auditing solution. One such solution is Lepide Active Directory Auditor, which enables users to pro-actively track, alert and report on changes being made to Active Directory.

Lepide’s Active Directory audit solution for records the details of every change made in the configuration of Active Directory and generates 90 reports in three different categories – Active Directory Modification Reports, Active Directory Security Reports, and Active Directory State Reports.

Below are some screenshots that show how our Active Directory auditing solution helps IT administrators track changes in Active Directory objects. Three reports are shown below; a report for objects created, objects deleted and objects modified.

  1. Object Created Report

Object Created Report - screenshot

  1. Object Deleted Report

Object Deleted Report - screenshot

  1. Object Modifications Report

Object Modifications Report - screenshot
You can also track other activities like successful and failed logon attempts, account lockouts, permissions changes, privilege user activities etc. easily with our solution.

The Final Note

Lepide Active Directory Auditor for can actually make the whole Active Directory auditing process simpler through its intuitive user interface and sending real-time alerts as emails to desired recipients, as updates to LiveFeed widget, and as push-notifications to Lepide Mobile App to ensure the security of your Active Directory environment.

Audit AD changes in real time with Lepide Active Directory Auditor
Fill in the rest of the form to
Get access to Lepide now
x