How to check when a user is added to a security group using ADAudit Plus

How to check when a user is added to a security group using ADAudit Plus

In this article  :

  • Objective

  • Prerequisites

  • Steps to follow

  • Validation and confirmation

  • Tips

  • Related topics and articles

 Objective   

This article explains how to track when a user was added to a security group using ManageEngine ADAudit Plus. It helps detect unauthorized additions, ensure compliance with access control policies, and maintain a clear audit trail of group membership changes.

 Prerequisites   

 Steps to follow 

  1. Log in to the ADAudit Plus web console as an administrator or with a technician account with delegated permissions to view Active Directory reports.

  2. Navigate to Active Directory > Group Management > Recently Added Members to Security Groups.

  3. Click Advanced Search above the reports.

  4. Select Member Name as a variable.

  5. Choose Contains as a condition.

  6. Enter the username in the Enter Search Value text box.

  7. Click Search to display relevant results.

  1. The reports can further be filtered using the following:

  • Specific user or group name

  • Time range

  • Domain controller or OU

Event IDs to look for (If validating in Event Viewer)  

Event ID

Description

4728

User added to a security-enabled global group.

4732

User added to a security-enabled local group.

4756

User added to a security-enabled universal group.

5136/5137

Group membership attribute modified (general object change logs).

 

Validation and confirmation  

  1. Verify that the added user appears in the Recently Added Members to Security Groups report.

 Tips 

  • Regularly review group management reports for unauthorized changes.

  • Schedule the report to run daily or weekly and email it to security administrators.

  • Regularly review high-privilege group changes (e.g., domain admins and enterprise admins).

  • Consider setting up real-time alerts in ADAudit Plus for critical group membership changes.

 Related topics and articles   

  • How to check when a user was removed from a security group

  • How to create a custom report to track group membership changes in privileged groups

                  New to ADSelfService Plus?

                    • Related Articles

                    • How to check who modified permissions on a folder using ADAudit Plus

                      In this article : Objective Prerequisites Steps to follow Validation and confirmation Tips Related topics and articles Objective This article explains how to track and identify who modified permissions on a folder using ManageEngine ADAudit Plus. It ...
                    • How to detect privilege escalations using ADAudit Plus

                      In this article: Objective Prerequisites Steps to follow Validation and confirmation Tips Related topics and articles Objective This article explains how to configure a real-time alert in ManageEngine ADAudit Plus to notify administrators whenever a ...
                    • How to view user logon and logoff times in ADAudit Plus

                      In this article: Objective Prerequisites Steps to follow Validation and confirmation Tips Related topics and articles Objective This article explains how to use ManageEngine ADAudit Plus to view detailed user logon and logoff times across ...
                    • How to configure Entra ID auditing in ADAudit Plus

                      In this article: Objective Prerequisites Steps to follow Validation and confirmation Tips Related topics and articles Objective This article explains how to configure Entra ID auditing in ADAudit Plus to monitor and track user activities, sign-ins, ...
                    • How to configure Workstations in ADAudit Plus

                      In this article: Objective Prerequisites Steps to follow Validation and confirmation Tips Related topics and articles Objective To configure Windows Workstations in ADAudit Plus using either the product console or command-line arguments, and to apply ...