- Configure Audit Policy Settings by running GPMC.msc → Edit "Default Domain Policy" → Computer Configuration → Policies → Windows Settings → Security Settings → Local Policies → Audit Policy → Audit account management → Define → Success.
- Configure object-level Active Directory auditing settings by opening ADSI Edit → Connect to "Default naming context"→ Click "OK" → Right-click DomainDNS object with the name of your domain → Properties → Security (Tab) → Advanced (Button) → Auditing (Tab) → Add Principal "Everyone" → Type "Success" → Applies to "This object and Descendant objects" → Permissions: → Select all check boxes except the following: "Full Control", "List Contents", "Read all properties", "Read permissions" → Click "OK".
- Enlarge security event log capacity by running GPMC.msc → Edit "Default Domain Policy" → Computer Configuration → Policies → Windows Settings → Security Settings → Event Log → Define:
a. Maximum security log size to 1gb
b. Retention method for security log to "Overwrite events as needed"
Run "gpupdate /force" command. - Run eventvwr.msc and filter security log for event id 4728 to detect when users are added to security-enabled global groups. The group name in our case is "Domain Admins".
- Run Netwrix Auditor → Navigate to "Alerts" → Find a predefined alert "Group Membership Changes" → Enable it: change "Mode" to "On".
- Double-click on the alert → Navigate to "Recipients" and specify email addresses you’d like the alert to be delivered to.
Whenever someone modifies the Domain Admins group, you will receive a similar alert: