Active Directory Auditing Requirements not satisifed
To comply with auditing requirements, we need to track (at real time) which delegated helpdesk user made changes in Active Directory via ADManager Plus.
For changes directly in Active Directory, this is possible via the Security Event Log on the Domain Controller. However all operations undertaken by delegated helpdesk users have a "Caller User Name" in the Event Log of the host server on which ADManager Plus is installed and NOT of the helpdesk user who made the change.
Can someone please explain if the credentials of the helpdesk user are impersonated by ADManager Plus directly, or whether a "service account" is used to perform operations in Active Directory?
Are the details of the helpdesk user available in real time by any other means?
New to ADSelfService Plus?