How to configure a custom alert to receive alerts for the group membership changes

How to configure a custom alert to receive alerts for the group membership changes

In this article:

  • Objective

  • Prerequisites

  • Steps to follow

  • Validation and confirmation

  • Tips

  • Related topics and articles

Objective  

This article explains how to create an alert profile in ManageEngine ADAudit Plus to monitor and receive notifications when group membership changes occur in specific security or distribution groups in Active Directory. This helps administrators detect unauthorized privilege escalations, maintain compliance, and ensure accountability for critical group modifications.

Prerequisites  

  • Have access to the ADAudit Plus web console.

  • Have a user account with Administrator privileges or a Technician account with delegated permissions to configure administrative settings.

  • Ensure that the following audit policy is enabled on all domain controllers.

    • Advanced Audit Policy Configuration > Account Management > Audit Security Group Management 

    • Setting: Enable Success for auditing successful events.

  • A system access control list must be configured for the desired security groups in Active Directory to track modifications.

  • All relevant domain controllers must be configured in ADAudit Plus and actively collecting logs.

  • To receive alert notifications via email from ADAudit Plus, ensure the SMTP settings are configured under Admin > General Settings > Server Settings.

 

Steps to follow

  1. Log in to the ADAudit Plus web console as an administrator or with a Technician account with delegated permissions to create or modify alerts.

  2. Navigate to the Alerts tab.

  3. Click New Alert Profile in the top-right corner.

  1. Enter a relevant Name and Description (e.g., Privileged Group Membership Change).

  2. Click the + symbol in the Report Profiles field.

  1. Under Domain, select the on-premises domain.

  2. In the Category drop-down, choose Group Modification.

  3. Search for and select the Security Group Membership Changes report profile. Click OK.

  1. You can tailor the Alert Message to suit your specific requirements.

  2. In Advanced Configuration, enable the Filter option, choose Add Filter, and define the criteria below.

    • Attribute: Group Name

    • Operator: equals

    • Value: Add the target groups you want to monitor (e.g., Domain Admins or Enterprise Admins).

  1. In the Alert Actions section, enable E-mail Notification.

  2. Enter the recipient email addresses where the alert should be delivered.

  3. Provide a clear and relevant subject line for the email notification.

  4. Select the preferred format for the alert email, either HTML or Plain Text.

  5. Select the details you would like to include in the email, such as:

    • Alert Message

    • Alert Profile Name

    • Event Details

  1. Enable the Throttle Notification option to suppress multiple alerts into a single notification based on defined criteria.
    Example: If multiple logon failures are detected from the same user within 15 minutes, consolidate them into one alert after that time window.

  2. If SMS provider settings are already configured in ADAudit Plus (Admin > General Settings > Server Settings > SMS), enable SMS Notifications for real-time updates.

  3. Enable the Execute Script option to trigger a script automatically when a specific alert is generated.
    Example: Lock a user account temporarily after detecting 10 consecutive logon failures from that account.

  4. If a ticketing tool is integrated with ADAudit Plus (Admin > Configuration > Ticketing system Integration), enable Configure Auto Ticketing to automatically generate tickets for alerts.

Note: You can also use Throttle Ticket Generation to avoid creating a ticket for every alert and instead generate one for a group of alerts meeting certain conditions.

  1. Click Save to activate the alert profile.

Validation and confirmation

  1. Manually add or remove a test user from any of the groups applied in the filter.

  2. Go to the Alerts tab and expand the on-premises domain under Profile Based Alerts.

  3. Select the alert profile that was created to view alerts in the ADAudit Plus console.

  4. Verify that the alert appears with the correct event details.

  5. Ensure the alert email is received at the specified address.

  6. If you configured a filter for specific groups, confirm that alerts are triggered only for those groups and not for others.

Tips

  • Focus on high-privilege and sensitive groups  . Prioritize alerts for critical groups such as:

    • Domain Admins

    • Enterprise Admins

    • Schema Admins

    • Any custom groups with elevated access to sensitive systems or data

  • Make alert names specific for better visibility in your dashboard and reports
    (e.g., Alert – Membership Change in Privilege Groups).

  • If desired, enhance alerting by adding a business hour filter to catch off-hours membership changes, which are often an indicator of malicious or suspicious activity.

Related topics and articles

  • How to check when a user is added to a security group

  • How to check when a user is removed from a security group

                  New to ADSelfService Plus?