Netwrix 1Secure 提供跨数据和身份的统一可见性——免费试用14天,享有完全访问权限。开始免费试用

资源中心操作指南

如何检测是谁在 Active Directory 中禁用了用户账户

如何检测是谁在 Active Directory 中禁用了用户账户

原生审计

  1. 运行 gpedit.msc → 创建新的 GPO → 编辑它 → 转到 "Computer Configuration" → Policies → Windows Settings → Security Settings → Local Policies > Audit Policy:
    • Audit account management → Define → Success.
  2. Go to Event Log → Define:
    • Maximum security log size to 4GB
    • Retention method for security log to Overwrite events as needed.
  3. Link the new GPO to OU with User Accounts → Go to "Group Policy Management" → Right-click the defined OU → Choose "Link an Existing GPO" → Choose the GPO that you’ve created.
  4. 强制更新组策略 → 在“Group Policy Management”中 → 右键单击已定义的 OU → 单击“Group Policy Update”。
  5. 打开 ADSI Edit → 连接到默认命名上下文 → 右键单击名称为你域的 DomainDNS 对象 → 属性 → 安全(选项卡) → 高级(按钮) → 审核(选项卡) → 添加主体“Everyone”→ 输入“Success”→ 应用于“此对象和子对象”→ 权限 → 选择除以下项外的所有复选框:
    • 完全控制
    • 列出内容
    • 读取所有属性
    • 读取权限 → 单击“确定”。
  6. 打开“事件查看器”,在“安全日志”中搜索事件 ID 4725(“用户帐户管理”任务类别)。
a user account was disabled in microsoft windows security auditing .

Netwrix Auditor for Active Directory

  1. 运行 Netwrix Auditor → 转到“搜索”→ 如果未选择,单击“高级模式”→ 设置以下筛选条件:
    • 筛选条件 = "Data source"
      运算符 = "Equals"
      值 = "Active Directory"
    • 筛选 = "详细信息"
      运算符 = "包含"
      值 = "用户账户已禁用"
  2. 单击“搜索”按钮,然后查看在 Active Directory 中是谁禁用了哪些用户账户。
a screenshot of the search page for a user account disabled .

分享到