Tek-Tips is the largest IT community on the Internet today!

Members share and learn making Tek-Tips Forums the best source of peer-reviewed technical information on the Internet!

  • Congratulations gkittelson on being selected by the Tek-Tips community for having the most helpful posts in the forums last week. Way to Go!

Who created an AD Account

Status
Not open for further replies.

spazman

Programmer
May 29, 2001
500
CA
I have searched here and google to no avail.

Does anyone know if AD stores WHO created an account? I have looked through the Schema and can't find it, however as you know the names aren't always what you think you are looking for.

If so, how do I access that info?

Thanks in Advance.
 
If you have auditing enabled for user account mgmt, then any new account changes would be showing up in the security event log under EventID 624
 
spazman,

Actually, with a little searching, you can usually identify who created an account. Look under the Security tab of the properties of the account. The user who created the account must have at least these four permissions (and probably a lot more):

Reset Password
Validated write to DNS host name
Validated write to service principal name
Write Account Restrictions


I have used this more than once to track down who created a computer account.

kmills
 
That won't work for user accounts, and may not always work for computer accounts.

If you want to always be able to document it, then you pretty much have to make it a policy/procedure to put notes on the account indicating who created it and why. Usually we just put in a reference to a ticket number in our helpdesk system since all account creations require a ticket. Then if we find one that doesn't have a note on it we disable the account.
 
Status
Not open for further replies.

Part and Inventory Search

Sponsor

Back
Top