How to configure an alert to notify when a user is moved between different OUs

How to configure an alert to notify when a user is moved between different OUs

How to create an alert to notify when a user is moved between different OUs  in Active Directory using ADAudit Plus

In this article:

  • Objective

  • Prerequisites

  • Steps to follow

  • Validation and confirmation

  • Tips

  • Related topics and articles

Objective  

This article explains how to configure an alert in ManageEngine ADAudit Plus to notify administrators whenever a user account is moved between organizational units (OUs) in Active Directory. Tracking such changes is vital for maintaining proper user account organization, enforcing access control policies tied to OUs, and identifying unauthorized or unintentional administrative actions.

Prerequisites   

  • Access to the ADAudit Plus web console.

  • A user account with Administrator privileges or a Technician account with delegated permissions to create and manage alert profiles.

  • All Domain Controllers must be:

    • Added and configured in ADAudit Plus.

    • Successfully collecting security logs in real time.

  • The following audit policy must be configured via GPO on all Domain Controllers.

    • Advanced Audit Policy Configuration > DS Access > Audit Directory Service Changes.

    • Setting: Enable Success for auditing successful events.

  • Ensure object level auditing is configured on user objects or OUs to track changes such as object movement.

  • To receive alert notifications via email from ADAudit Plus, ensure the SMTP settings are configured under Admin > General Settings > Server Settings.

 

Steps to follow

  1. Log in to the ADAudit Plus web console as an administrator or with a Technician account with delegated permissions to create or modify alerts.

  2. Navigate to the Alerts tab.

  3. Click New Alert Profile in the top-right corner.

  1. Enter a relevant Name and Description (e.g., User Moved Between OUs).

  2. Click the + symbol in the Report Profiles field.

  1. Under Domain, select the on-premises domain.

  2. In the Category dropdown, choose User Modification.

  3. Search for and select the Renamed or Moved Users report profile. Click OK.

  1. You can tailor the Alert Message to suit your specific requirements.

  2. Additionally, the Advanced Configuration options allow you to customize alerts based on thresholds, business hours, and advanced filtering criteria.

  3. In the Alert Actions section, enable E-mail Notification.

  4. Enter the recipient email addresses where the alert should be delivered.

  5. Provide a clear and relevant subject line for the email notification.

  6. Select the preferred format for the alert email, either HTML or Plain Text.

  7. Select the details you would like to include in the email, such as:

  • Alert Message

  • Alert Profile Name

  • Event Details

  1. Enable the Throttle Notification option to suppress multiple alerts into a single notification based on defined criteria.
    Example: If multiple logon failures are detected from the same user within 15 minutes, consolidate them into one alert after that time window.

  2. If SMS provider settings are already configured in ADAudit Plus (Admin > General Settings > Server Settings > SMS), enable SMS Notifications for real-time updates.

  3. Enable the Execute Script option to trigger a script automatically when a specific alert is generated.
    Example: Lock a user account temporarily after detecting 10 consecutive logon failures from that account. 

  4. If a ticketing tool is integrated with ADAudit Plus (Admin > Configuration > Ticketing system Integration), enable Configure Auto Ticketing to automatically generate tickets for alerts.

Note: You can also use Throttle Ticket Generation to avoid creating a ticket for every alert and instead generate one for a group of alerts meeting certain conditions.

  1. Click Save to activate the alert profile.

Validation and confirmation

  • Simulate a test movement.

  • Go to the Alerts tab and expand the on-premises domain under Profile Based Alerts.

  • Select the alert profile that was created to view alerts in the ADAudit Plus console.

  • Verify that the alert appears with the correct event details.

    • USER NAME: User account that got moved.

    • OBJECT OLD DN: The source OU of the user account.

    • OBJECT NEW DN: The destination OU of the user account.

    • MODIFIED TIME: The time of the action.

    • CALLER USER NAME: The name of the user who performed the move.

  • Ensure the alert email is received at the specified address.

 

Tips

  • Monitor the movement of privileged or sensitive accounts.

  • Create additional alert profiles specifically for high-impact OUs.

 

Related topics and articles

  • How to check when a user was added to a security group

  • How to check when a user was removed from a security group

                  New to ADSelfService Plus?