I want to keep an audit when I remove or add users from local groups. Is it possible to filter out which groups? If not, all local groups is fine.
With Windows 2008 R2 how do I audit when an user is added and removed from a local group?
725 Views Asked by Chaka At
1
There are 1 best solutions below
Related Questions in WINDOWS-SERVER-2008-R2
- IIS7 SQL ODBC and Server 2008 R2 (converted site from IIS6 2003 to 2008 R2 IIS7)
- Problems installing PHPMailer on Windows 2008 server r2 configured w/ iss 7.0
- ASP.Net 1.1 app on IIS 7 waiting threads
- Blank path in environment variable causing elevated command prompt to not respond
- What are the PHPMailer requirement for sending mail and receiving mail in IIS 7
- Set interval for Automatic (Delayed Start) Windows Services
- Why can't I access 'Advanced Settings' on an IIS website with only a net.tcp binding?
- Error installing Chocolatey via Ansible on Windows
- X509Store Certificates.Find FindByThumbprint
- Powershell script as executable giving "wrong" giving return code -1 in Bamboo
- Could AWE or anything else could help to use more SQL memory
- Connectiong Remotely To Windows Server 2008r2 Core DNS_INFO_NO_RECORDS
- WCF Service returning HTTP 405 in a POST
- Powershell Error when run on a different machine
- Do I need Windows Server 2012 and VS 2012 or 2013 to write plugins for MS CRM 2015?
Related Questions in AUDITING
- Particular ServiceControl auditing and Bus.HandleCurrentMessageLater();
- How to implement tungsten replicator BuildAuditTable filter
- How to PROVE that some Oracle Stored Procedure has been called without auditing it?
- Tracking of who created or changed an entity in microservices
- Javers - What are advantages of using Javers instead of Envers?
- Auditing Parallel .Net Services in DB Table
- Oracle SYS.AUD$ Audit Actions
- "audit create session by session" vs. "audit create session by access"?
- C# reflection and auditing types
- Using table auditing in order to have "snapshots" of table
- audit log for any persisted changes, without using database triggers, instead use spring/hibernate
- Meteor Auditing Code Cost - organized (iron-router) vs one file?
- Should I monitor the SQL Server tempdb for user activity?
- With Windows 2008 R2 how do I audit when an user is added and removed from a local group?
- Audit on @Embeddable objects with SpringBoot annotations
Trending Questions
- UIImageView Frame Doesn't Reflect Constraints
- Is it possible to use adb commands to click on a view by finding its ID?
- How to create a new web character symbol recognizable by html/javascript?
- Why isn't my CSS3 animation smooth in Google Chrome (but very smooth on other browsers)?
- Heap Gives Page Fault
- Connect ffmpeg to Visual Studio 2008
- Both Object- and ValueAnimator jumps when Duration is set above API LvL 24
- How to avoid default initialization of objects in std::vector?
- second argument of the command line arguments in a format other than char** argv or char* argv[]
- How to improve efficiency of algorithm which generates next lexicographic permutation?
- Navigating to the another actvity app getting crash in android
- How to read the particular message format in android and store in sqlite database?
- Resetting inventory status after order is cancelled
- Efficiently compute powers of X in SSE/AVX
- Insert into an external database using ajax and php : POST 500 (Internal Server Error)
Popular Questions
- How do I undo the most recent local commits in Git?
- How can I remove a specific item from an array in JavaScript?
- How do I delete a Git branch locally and remotely?
- Find all files containing a specific text (string) on Linux?
- How do I revert a Git repository to a previous commit?
- How do I create an HTML button that acts like a link?
- How do I check out a remote Git branch?
- How do I force "git pull" to overwrite local files?
- How do I list all files of a directory?
- How to check whether a string contains a substring in JavaScript?
- How do I redirect to another webpage?
- How can I iterate over rows in a Pandas DataFrame?
- How do I convert a String to an int in Java?
- Does Python have a string 'contains' substring method?
- How do I check if a string contains a specific word?
You're basically looking for two events in the Security eventlog.
4732A member was added to a security-enabled local group.4733A member was removed from a security-enabled local group.When using the following commandline you get a new instance of the eventviewer filtered on those two events.
An other option is to use the WMIC tool from the commandline (make sure you are using an elevated commandprompt)
Do notice that this uses Win32_NTLogEvent internally and I had to use the
/trace:onswitch to figure out the correct syntax for the where clause.Use the optional
/record:filename.xmlto store the results in an xml file or simply redirect the output to a csv file.One other option you have is to use powershell:
Last one I povide is by writing a small c# program that uses the EventLog class
Take your pick