Re: DNS entry deletion tracking
"Brendon B" <BrendonB@discussions.microsoft.com> wrote in message
news:E568207F-68A3-4EF2-8621-FEEB9CE0C658@microsoft.com...
> Hi Everyone
>
> One of the administrators here deleted an A entry in our 2003 Active
> Directory Integrated DNS. Is there a way to track the user who did this?
i.e
> In Logs? I'm not sure if the will be logged in the security logs of the
> Domain Controllers? Would looking for a 564 Security Audit (Object
Deleted)
> event pick this up?
Not unless you have enabled the appropriate auditing setting
(DS objects) AND selected the AD DNS objects to be auditing
with ACLs. (both unlikely.)
> Your is appreciated
Do you perhaps have too many admins?
|