To set up an alert in ADAudit Plus that automatically notifies administrators whenever an OU is created in Active Directory, helping ensure prompt awareness of critical changes.
You need access to the ADAudit Plus web console.
You need the admin role or any technician account delegated with permissions to configure an alert.
Please ensure all the devices or the applicable device is configured in ADAudit Plus and is collecting logs.
Go to the Alerts section from the top menu.
Click + New Alert Profile.
Enter a name for the alert profile (e.g., OU Creation Notification).
Provide a brief description outlining the purpose of the alert.
Under Report Profiles, click on the + icon to add a report.
Select the On-Prem Domain from the drop-down.
From the list, choose the OUs Created report.
Click OK to confirm.
Tailor the Alert Message to suit your specific requirements.
Under Advanced Configuration, customize the alerts based on thresholds, business hours, and advanced filtering criteria.
In the Alert Actions section, check the Email Notification box.
Enter recipient email addresses.
Provide a clear and relevant subject line for the email notification.
Select the preferred format for the alert email, either HTML or Plain Text.
Use the check boxes to select the details you would like to include in the email:
Alert Message
Alert Profile Name
Event Details
Check the Throttle Notification box to suppress multiple alerts into a single notification based on defined criteria.
Example: If multiple logon failures are detected from the same user within 15 minutes, consolidate them into one alert.
If SMS provider settings are configured in ADAudit Plus (Admin > General Settings > Server Settings > SMS), check the SMS Notification box for real-time updates.
Check the Execute Script box to trigger a script automatically when a specific alert is generated.
Example: Lock a user account temporarily after detecting 10 consecutive logon failures from that account.
If a ticketing tool is integrated with ADAudit Plus (Admin > Configuration > Ticketing System Integration), check the Configure Auto Ticketing box to automatically generate tickets for alerts.
Note: You can also use Throttle Ticket Generation to avoid creating a ticket for every alert and instead generate one for a group of alerts meeting certain conditions.
Click Save to activate the alert profile.
For faster alerting, ensure real-time log collection is configured for all domain controllers.
Name alerts clearly (e.g., Alert: New OU Created in Production Domain) to identify these activities and respond quickly.
Consider configuring alerts for OU deletions or modifications to cover the full change life cycle.
Ensure only authorized users have rights to create OUs to reduce accidental or unauthorized changes.