To track changes in Active Directory, you first need to enable Active Directory auditing through Group Policy and configure auditing for the AD objects or containers you want to monitor. You can then review Active Directory audit logs in the Security log on your domain controllers to find out who made a change, what was changed, and when it occurred.
Directory Service Changes events (5136–5141) record changes such as AD objects being created, modified, moved, restored, or deleted, while Account Management events (47xx) record activities such as user account and security group changes.
This article explains how to enable AD auditing using Group Policy Management Console (GPMC), configure object-level auditing using ADSI Edit, and review AD audit logs using Event Viewer and relevant Windows Security event IDs. It also explains how Lepide can simplify Active Directory change auditing with centralized monitoring, reporting, and alerting.
How to Enable Active Directory Auditing Using Group Policy
Please follow the steps:
- Sign in to a domain controller with appropriate administrative privileges. Open Server Manager → Tools → Group Policy Management.
- In the Group Policy Management Console, expand Forest → Domains → Your Domain → Domain Controllers. Right-click Default Domain Controllers Policy and select Edit. Alternatively, you can edit a dedicated GPO linked to the Domain Controllers OU.
- In the Group Policy Management Editor, navigate to:
Computer Configuration → Policies → Windows Settings → Security Settings → Advanced Audit Policy Configuration → Audit Policies
- Expand DS Access, double-click Audit Directory Service Changes, select Configure the following audit events, enable Success, and click OK.

- Expand Account Management and configure the following audit subcategories:
- Audit User Account Management – Enable Success and Failure.
- Audit Computer Account Management – Enable Success and Failure.
- Audit Security Group Management – Enable Success and Failure.

- Close the Group Policy Management Editor. The updated policy will be applied during the normal Group Policy refresh cycle. To apply the policy immediately on a domain controller, open Command Prompt as an administrator and run:
gpupdate /force
Configure Active Directory Object Auditing Using ADSI Edit
After enabling Audit Directory Service Changes in Group Policy, configure auditing on the Active Directory objects or containers whose changes you want to track.
- Sign in to a domain controller with appropriate administrative privileges. Press Windows + R, type adsiedit.msc, and press Enter.
- In ADSI Edit, right-click ADSI Edit and select Connect to.
- Under Select a well known Naming Context, select Default naming context, and click OK.
- Expand the Default naming context and locate the domain, organizational unit (OU), or container that you want to audit.
- Right-click the object or container and select Properties.
- Select the Security tab, click Advanced, and then select the Auditing tab.
- Click Add, and then click Select a principal. Specify the users or groups whose changes you want to audit. To audit changes made by all users, select Everyone.
- Set Type to Success and choose the appropriate option under Applies to. If you are configuring auditing on an OU or container, select the appropriate descendant scope if you also want to audit changes to objects beneath it.
- Under Permissions, select the operations you want to audit, such as creating or deleting objects, writing properties, or modifying permissions.

- Click OK to save the auditing entry, and then click OK again to close the Advanced Security Settings and Properties windows.
How to Review Active Directory Audit Logs in Event Viewer
After configuring the required audit policies and object auditing, you can review Active Directory changes in the Security log on a domain controller.
- Open Server Manager → Tools → Event Viewer.
- Navigate to Windows Logs → Security.
- Click Filter Current Log in the Actions pane.
- In the <All Event IDs> field, enter the event IDs for the types of Active Directory changes you want to investigate.

Directory Service Changes
User Account Changes
Security Group Membership Changes
- Click OK to display the matching events.
- Open an event and review its details to determine who performed the action, which account or Active Directory object was affected, when the change occurred, and other information associated with the event.

For Event ID 5136, review fields such as Subject, Object, Attribute LDAP Display Name, Attribute Value, and Operation Type. An attribute modification can generate separate events showing Value Deleted for the previous value and Value Added for the new value.
How Lepide Active Directory Auditor Tracks Changes Made in AD
For many users, manual auditing can be both time-consuming and unreliable, as you have to search lots of audit logs in the Event Viewer; it does not generate instant alerts and reports for Active Directory changes.
It is therefore recommended that you opt for an automated Active Directory auditing solution. One such solution is Lepide Active Directory Auditor, which enables users to pro-actively track, alert and report on changes being made to Active Directory.
Lepide’s Active Directory audit solution for records the details of every change made in the configuration of Active Directory and generates 90 reports in three different categories – Active Directory Modification Reports, Active Directory Security Reports, and Active Directory State Reports.
Below are some screenshots that show how our Active Directory auditing solution helps IT administrators track changes in Active Directory objects. Three reports are shown below; a report for objects created, objects deleted and objects modified.
- Object Created Report

- Object Deleted Report

- Object Modifications Report

You can also track other activities like successful and failed logon attempts, account lockouts, permissions changes, privilege user activities etc. easily with our solution.
The Final Note
Lepide Active Directory Auditor for can actually make the whole Active Directory auditing process simpler through its intuitive user interface and sending real-time alerts as emails to desired recipients, as updates to LiveFeed widget, and as push-notifications to Lepide Mobile App to ensure the security of your Active Directory environment.