This article explains how to configure a real-time alert in ManageEngine ADAudit Plus to notify administrators whenever a user is added to a privileged Active Directory group, such as Domain Admins.
You must have access to the ADAudit Plus web console with an administrator account or a technician account that has permissions to create and manage alert profiles.
Your on-premises Domain Controllers must be configured in ADAudit Plus and successfully collecting security logs.
If you wish to receive notifications, the relevant services must be configured:
Email: SMTP server settings must be configured under Admin > General Settings > Server Settings.
SMS: Your SMS provider must be configured under Admin > General Settings > Server Settings > SMS.
Tickets: Your ticketing tool must be integrated under Admin > Configuration > Ticketing system Integration.
Enter a relevant Name and Description (e.g., "User Added to Domain Admins").
In the Report Profiles field, click the + symbol to add a report.
In the Select Report Profile window:
Under Domain, select your on-premises domain.
In the Category dropdown, choose Group Modification.
Select the Security Group Membership Changes report profile, then click OK.
Under Advanced Configuration, check the Filter box to enable advanced filtering.
Configure the first filter to specify the privileged group:
Click Add filter.
Set the filter to Group Name | equals | [Click on add to choose the group, e.g., Domain Admins].
Configure the second filter to look for additions to the group:
Click the plus icon (+) to add another filter row.
Ensure the operator is set to AND.
Set the new filter to Message | contains | added.
In the Alert Actions section, enable your preferred notification methods:
E-mail Notification: Check the box, enter the recipient email addresses, and customize the subject and content.
SMS Notification: Check the box to send real-time SMS alerts.
Execute Script: Check the box to run a script automatically, such as one to temporarily lock the user account that was added.
Configure Auto Ticketing: Check the box to automatically generate a ticket in your integrated help desk system.
Click Save to activate the new alert profile.
Ensure the alert email and any other configured notifications (SMS, ticket) were received at the specified destinations.
Create separate alert profiles for different high-privilege groups (e.g., Enterprise Admins, Schema Admins) for more granular monitoring.