Subscribe to Windows IT Pro

 

Get Newsletters

  • Get the Latest News
  • Product Updates
  • Helpful Tricks
  • Productivity Tips

Subscribe Now!

December 12, 2008 12:00 AM

Active Directory Auditing Tools

Not all AD auditing tools audit all of AD
Windows IT Pro
InstantDoc ID #100828
Rating: (4)

Active Directory (AD) is a crucial component of just about any Windows-based IT infrastructure, and keeping tabs on who modified AD records, when they were changed, and why they were changed can be a full-time job. Throw in some additional requirements—such as the need to be in compliance with federal and state governance guidelines, from the Sarbanes-Oxley (SOX) Act to the Health Insurance Portability and Accountability Act (HIPAA)—and you have the makings of a headache-inducing task for many IT pros. But help is on the way.

Windows Server 2008 AD Improvements

Microsoft listened to IT pro complaints about AD auditing and implemented several new features in Windows Server 2008 to ease the pain. “Windows 2008 brings various benefits to the table with respect to event management, including a completely changed event-log storage model,” says Guido Grillenmeier, a Microsoft Directory Services MVP and a master technologist with HP’s Advanced Technology Group. “It also includes improved native AD auditing, as it allows more granular and more complete auditing of AD changes. For example, it can record the old value and new value of an attribute that was changed.”

Server 2008 breaks auditing into four categories: Access, Changes, Replication, and Detailed Replication. The Changes category improves upon the way AD changes were handled in Windows Server 2003 and Windows 2000, logging deltas of attribute changes, detailing new object creation and movement, and offering a create-event feature that’s triggered when objects are moved to different domains.

Choosing an AD Auditing Solution

Regardless of whether you’re running Server 2008, Windows 2003, or Win2K, an off-the-shelf AD auditing product can help minimize the workload. Determining what level of AD auditing your organization needs is important . Grillenmeier cautions against looking for a silver-bullet solution to AD auditing requirements. “For example, proxy-management solutions … such as AD Self-Service Suite and Ensim Unify … are nice tools to delegate specific management tasks to non-admin users and audit the changes they do to AD with the tool. However, these tools only audit what’s changed by them and can’t audit native changes in AD; they can never create a complete auditing trail.”

Grillenmeier contrasts those AD proxy-management auditing tools with AD auditing tools that gather security and auditing events from event logs on domain controllers (DCs)—such as Microsoft System Center Operations Manager or HP OpenView—and AD auditing tools that combine native event logs with AD data gathered by agents, such as Quest InTrust and Quest ChangeAuditor (formerly NetPro ChangeAuditor).

“Event-log–based [auditing] may be sufficient for many customers that need to meet specific compliancy requirements,” says Grillenmeier. “It’s mainly a matter of correctly setting up auditing in the directory itself, so that the changes are correctly logged in the event logs. Note that if proxy-management tools are used, you still have to combine the native event data with the data of the proxy tools to figure out which person actually performed a change in AD, since for changes done by the proxy tool the native event logs will only see the service account as the owner of the change.” Grillenmeier says that only products that combine event-log auditing with separate agents that gather AD data are capable of auditing all AD changes.

Tom Crane, a product manager for InTrust at Quest Software, says that the most useful products offer the ability to capture AD change information not provided by the version of Windows Server you’re using. “Some AD change information doesn’t appear in the event log. For example, some changes are consolidated down into a single event message, and that single event may contain multiple changes. Having a tool that is able to provide that information will help reduce time spent in troubleshooting AD auditing problems.”

Don’t Forget the Data

One important yet overlooked aspect of AD auditing is the massive amount of data the auditing process can generate. “For enterprise-scale customers, this easily amounts to many gigabytes per day of auditing data,” Grillenmeier says. “Tools that [have the capability] to efficiently store the auditing data in a compressed format and [automatically clean up that data over time] are a critical factor for large companies.” You’ll do well to consider your organization’s auditing needs, the number of AD changes it makes, and how granular those changes are. And you’d be well advised to pay attention to the security, backup, and disaster recovery of AD auditing data, just as you would for other types of data.

View the AD Auditing Tools Buyer's Guide table. [pdf]

Related Content:

ARTICLE TOOLS

Comments
  • Howard Simpson
    3 months ago
    Nov 29, 2011

    Another Active Directory auditing tool is XIA Configuration. It supports multiple domains, group policy settings, schema configuration, functional levels and trusts.

    Find out more here (hopefully this will turn out to be a link, apologies if not!)
    <a href="http://www.centrel-solutions.com/XIAConfiguration/capabilities.aspx?capability=ActiveDirectory" >audit Active Directory</a>

  • Mikhail
    3 years ago
    Sep 18, 2009

    Sorry, the correct link is: http://www.netwrix.com/active_directory_change_reporting_freeware.html

  • Mikhail
    3 years ago
    Sep 18, 2009

    NetWrix Active Directory Change Reporter had this "agentless" technology with "before" and "after" values since the very first version. And this product even has a freeware version.

    Product link:
    http://netwrix-dev.netwrix.com/active_directory_change_reporting_freeware.html

    P.S. Disclose of affiliation: I work for NetWrix.

  • Gerald
    3 years ago
    May 27, 2009

    A new version 5.1 of scriptlogic's active administrator includes an enhanced active directory auditing capabilities.

    This tool does not require any agents to be installed on a domain controller and can collect “before” and “after” values for any attribute changes on active directory objects.

    http://www.scriptlogic.com/products/activeadmin

  • excg2002
    3 years ago
    Apr 29, 2009

    THXS

You must log on before posting a comment.

Are you a new visitor? Register Here

advertisement

advertisement

White Papers

Get your Windows 7 deployment off to the right start by implementing PC lockdown. A locked-down environment is easier and cheaper to support since users are less likely to make unnecessary changes to the core system configuration - read more here!

Essential Guides

Is your iSCSI "lossy"? The reality is that most off-the-shelf Ethernet hardware deployed for iSCSI can lose packets, resulting in slow performance or application downtime. Learn how to assess your current iSCSI infrastructure and engineer an advanced iSCSI SAN infrastructure.

Web Seminars

What's the best way to keep your network safe from malware? In this web seminar, security expert Greg Shields suggests an alternative method to the traditional blacklisting approach that is common with anti-virus and anti-malware solutions.

eLearning Series

We bring the experts direct to you to share their real-world perspective and expertise. During each event, three sessions stream in real time, so you can learn, ask questions, and get solutions.
Upcoming event: Getting the Most with Exchange 2010 with Paul Robichaux

Subscribe to Windows IT Pro!

Windows is a trademark of the Microsoft group of companies. Windows IT Pro is used by Penton Media Inc. under license from owner.