AdAudit API
Is there any API for AdAudit plus ?
Detect Change of Login location (IP Address)
Is there a way to identify that a user has logged into domain (via app login or via vpn) from a new location than previously? For instance, a user logs into an app from work computer; then he/she uses home computer. Is there any way to capture such change of location and which product would be suitable? Thanks in advance for any tips. -Anna
ADAudit Plus Roadmap - 2022/2023
Hi there, Is there a roadmap for the product ADAudit Plus for the upcoming years? I'm specially looking for changes / improvements in the User behavior analytics (BUA) tool section. Thanks a lot for your time. Cheers Arthur
New Script Based Alert Action
Guys, I see in build 5040/5041 you have added the option to fire a script on an alert! This is something I have wanted/asked for for a long time so I am delighted to see that it's made it into the product. Is there any documentation on this feature i..e what script types are allowed (VBScript, powershell etc) and what variables can be passed to that script?
ManageEngine ADAudit Plus Build Number: 5000, has been released.
Dear All, Greetings from ManageEngine ADAudit Plus! ADAudit Plus latest build 5000 has introduced a new feature 'Search Archived Events'. Using this feature, you can now track specific events from the archive files in a very efficient way. The release also includes other enhancements and fixes, as mentioned below. With ADAudit Plus, enhance your Windows Server environment auditing [Active Directory, workstation, file servers, member servers, EMC, NetApp Filers, printers & USB] to meet the most-needed
Report for several accounts
I want create a script that shows logon data for all my service accounts, 100+ accounts. This is to satisfy an audit requirement and assist in identifying where these accounts are used How can I create this report? Do I need to access the DB directl
Azul Zulu Java Multiple Vulnerabilities (2023-01-17)
I am seeing ADAudit Plus flagged for this vulnerability by Tenable/Nessus, running on the latest version of ADAudit+ Azul Zulu Java Multiple Vulnerabilities (2023-01-17): https://docs.azul.com/core/zulu-openjdk/release-notes/january-2023
Custom Work Hours Report
Can we create a custom work hours report? I want to provide a work hours report that looks just like the one you see on the page that only shows the following columns and no underlying log detail. I need a report I will run every Monday to report the
File Server - FSRM Quota Reports/Alerts
Does the File Server module include fsrm quota threshold reporting and notifications? We use FSRM quotas for our systems, and we intentionally set hard quotas in FSRM. Because FSRM email notification setup only works out of the box with Exchange server
CIS Benchmark
Hi. When CIS Benchmarks for Windows version 4 will be added ?
Can 'Custom Period' make use of variables?
We would like to be able to create a custom period that is set to the past 30 days or the past week. I can't seem to find a way to do it. I only seem able to create a period of specific dates.
How I costomize log on page
Hi, I need costomize the logon page, How I do this? Thanks
ADAudit plus to exclude DFS staging folder from auditing
Hi, We have purchased AdAudit plus and taking advantage of its Web-Based Windows File Server Auditing feature. However, like other Windows file replication service (DFS) implementations, We've deployed and configured two-way replication between our 2 file servers for fault tolerance purposes of files. How do we exclude DfsrPrivate\Staging folder and its filetypes from auditing?? This adds unnecessary and numerous amount of data that I do not want to see in file audit reports (shown below). Thanks,
Trying to get rid of Kerberos UNconstrained delegation
We have some computer accounts that have Kerberos UNconstrained delegation configured and want to switch to Kerberos constrained delegation. However to do this we need to know which services these accounts are requesting a ticket for in the backend (ex. MSSQLSvc/SQLSRV01:8080).
NTLM for authentication - Report
Hi My I know if "Ad Audit" have features or report to show me, How can I find out if my clients are using NTLM for authentication instead of Kerberos against specific Windows servers, applications, or services Find the machine/application/services using NTLM for authentication ? That will show me in the report
ADAudit is not capturing event ID 4769
Hello, I am looking in Profile Based Reports -> Account Logon - All Users Logon and this report does not capture even ID 4769 (Kerberos service ticket has been requested). This does not make sense as I see the events in the Security Log on my domain controllers,
ADAudit archiving and MS SQL
Hello everyone. I need some advice with our situation:we have ADAudit running for a few years now,and have archiving enabled.The archiving works, the archive files get created on the destination folder, but as far as I can tell, none of the data gets
New SSL cert
I see ADManager has a GUI to replace the cert How do you update the cert for ADAudit?
Use ADAuditplus to find zombie accounts
Hello, Is there a possibility in ADAuditPlus to track accounts who are: -Active -Not used 4 a long time. (e.g. based on last logon attempt) With a report like this, we could be able to find 'zombie accounts'. kind regards
Attention! There's a potential security.
Attention! There's a potential security risk with the ManageEngine ADAudit Plus upgrade file (ManageEngine_ADAudit_Plus_8_0_0_SP-0_2_0.ppm). Virustotal analysis indicates it might contain a Trojan.luckyMouse.r Here is the report https://www.virustotal.com/gui/file/17ce8f681cad09eb9c2ca8ca60215f539d7c3cdd215eaf259f0b2879bd599621?nocache=1
ADFS reports - how?
The latest version of ADAP now does login reports for ADFs. These reports are currently empty. How do I configure or enable them? Thanks
ADAudit Plus multiple domain configuration
Hello, I'm trying setup ADAudit Plus auditing multiple domains from one instance. ADAudit instance running in domain A under service account. When I'm trying to configure Audit Policy using button, it failing with PolicyStatusUnspecified error - Error Code:80004005 Even if adding domain B under domain B admin permissions. I'm wondering if someone succeed set up ADAudit plus running multiple domains with all audit features. What accounts setup and permissions should be used for this.
Explanation of the "TIMESTAMP OF LAST EVENT"
In the 'Domain Settings' next to each domain controller it reports the TIMESTAMP OF LAST EVENT. Could someone explain what that means exactly? The reason for asking is that I have ten DCs, eight of them show a TIMESTAMP OF LAST EVENT for today but two of them show TIMESTAMP OF LAST EVENT for several days ago. Many thanks
Report that lists all accounts?
I need to create a report of all enabled user accounts and disabled user accounts. I am only seeing reports for "recently" enabled/disabled, but I need to see all of them. How do I just get a report of all the accounts?
Schedule Backup database
Hi In some ManageEngine products, database backup can be performed automatically by setting a schedule for that. Is this feature going to be added to ADAudit Plus soon? Regards Rochdi
Looking for a report listing all machines that use the domain administrator account
I need to change our built-in domain admin account password, so I would like to get a list of every server that's logging in with that account. When I run user logon reports for Administrator, I get over 130,000 logs, mostly just domain controller activity.
Logs of when ADAudit accesses a server
I receive alerts about possible intrusion events. The account we set in ADAudit is the account being flagged. Is there a log that I can view that shows when ADAudit accessed a server and directory at a specific time to verify this is legit activity?
Automated Reporting Customization
Hey there, So far, I have enjoyed using ADAudit Plus, however the canned reports are rather limiting. For example, the Recently Modified Users report is displaying a lot of msExchMailboxAuditLastAdminAccess logs. Although this information is helpful to log, I would not want this included in my report nor any false positives, I would prefer to only have any anomalies sent to my e-mail. How are your clients leveraging the reporting? In my case, what options are available for me to customize these reports
ADAudit and Netapp ONTAPI (ZAPI) EOL.
NetApp are in the process of phasing out their old ONTAPI (ZAPI). ONTAP 9.13.1 software will be the final version to offer normal support of ONTAPI. ONTAPI access re-enablement will not be supported on ONTAP 9.18.1 As ADAudit uses ZAPI (We do need to
DCSync
Hi, Is there a way to exclude the msol_user account from being reported in the DCSync attack events? As I understand it, the msol account is designed for this?
Auto add Member servers
Is there a way to script the auto add of new member servers into AD Audit? Doing this manually is a waste time. Thanks!
Remote Desktop Gateway Server audit
How do I setup Remote Desktop Gateway Server audit in the newest version? Thanks!
GUI for SSL management
Hello ADAP Team. I am ZOHO customer many years and during this time I viewed that many yours product obtain normal GUI for SSL management (like EC, OpManager, ADManager) but ADAP still living without it ( Why? When ADAP also will be with normal SSL management
ActiveSync Devices Under Account Lockout Analyzer
Hello we have a user that keeps getting locked out. Under the Account Lockout Analyzer, I see three "devices" within the ActiveSync Devices. Does this mean those three devices are causing the lockouts? In https://outlook.office365.com/ecp/ Phone > Mobile
Alert when user is moved out of a specific OU
I am trying, unsuccessfully, to create an alert profile that will alert when a user is moved OUT of a specific OU. I have been successful in creating an alert for when a user is moved IN to a specific OU, but not the reverse. Any help would be app
No option to add email and phone number to adaudit report.
I am attempting to run a report for new AD users created between xyz and xyz that includes all information from there AD account. Including phone number and email address as we populate those fields when creating the AD account. However I don't find where I can add those as a column in the report. Does anyone have information on this?
ADAudir Send alert to telegram
hi, i tried configured ADAudit send report to telegram, i configured sms setting as API TG but settings not Save - "Enter valid HTTP URL.". how can i make ADAudit use Telegram for alerts
Local Domain Admin Activity
Hi, I have several thousand users across multiple locations and I am trying to find users who login to a local machine with local credentials. The local user account is an admin and I want to see how I can find these users. The account name is the same across all machines.
ADAudit: an alert that notifies me when a user is logged in for more than 24 hours
Greetings. I would like to create in ADAudit an alert that notifies me when a user is logged in for more than 24 hours. In the online demo I have seen that the administrator can define alerts through ‘Configuration --> Create Alert Profile’ and then you
Detecting the Windows domain controller vulnerability? (CVE-2020-1472)
Microsoft has created new event ID's to help identify devices that use the vulnerable connection. Can this be added or an alert created for it? Source: https://support.microsoft.com/en-us/help/4557222/how-to-manage-the-changes-in-netlogon-secure-channel-connections-assoc. Can this be added into ADAudit? Specifically, this part: Deploy the August 11th updates to all applicable domain controllers (DCs) in the forest, including read-only domain controllers (RODCs). After deploying this update patched
Next Page