Back

learn.microsoft.com

Source: learn.microsoft.com

Published:

<p>I am trying to figure out how to audit where group changes are initiated in AD. Auditing is enabled and aggregates in a SIEM.</p> <p>When a change occurs I see this chain of event IDs:</p> <p>4662 - An operation was performed on an object.</p> <p>4732 - A member was added to a security-enabled lo

Read original article

Loading article...

Article not found