Tek-Tips is the largest IT community on the Internet today!

Members share and learn making Tek-Tips Forums the best source of peer-reviewed technical information on the Internet!

  • Congratulations Chris Miller on being selected by the Tek-Tips community for having the most helpful posts in the forums last week. Way to Go!

Logging a Users Movements

Status
Not open for further replies.

lagcat

Technical User
May 18, 2007
52
GB
Hello,

we have hit a problem where a member of staff has been given domain admin privilages....and because of management we are unable to remove this

is there a way to log the activity around the domain to see servers/areas the user has accessed? we are hitting to problem where we think the user may way to access other users private folders and e-mails...and we need a way to log it

Cheers

CCENT, CCNA
MCP, MCSA
Comptia: Network Essentials, Security +, A+
 
Domain admins shouldn't have access to those things. Turn on auditing for file access, Exchange server access is rather more tricky but you can block that for the user in ESM then it doesn't matter.

If management won't allow you to remove the access you need to trust the individual - this sounds like a can of worms so be very careful what people ask you to do.
 
Make sure they sign an IT Policies and Procedures agreement, so if and when u fire them, u r covered.

This will also let them know that you are watching them.

Google for tools that will track AD changes; there are many out there.

Maybe someone could recommend one?
 
Status
Not open for further replies.

Part and Inventory Search

Sponsor

Back
Top