Vyapin Software Systems

Microsoft Network Partner

 
 
 
     
 
Active Directory Change Tracker
Version 1.1

Last Updated: May 15, 2012

 

Pros & cons of Active Directory auditing

 
  • Active Directory audit events are stored in Security event logs in domain controllers. The number of events generated generally depends on the number of audited objects and the SACLs set on the objects. Event logs grow in size very quickly over a period of time and require constant cleanup and backup. Event log data is not replicated across domain controllers and hence it is necessary to gather event log data from all the domain controllers in order to get all the audited events archived in one place. Enabling audit always produces some load on the domain controllers and hence auditing must be restricted to the most critical and essential objects in your Active Directory. However, auditing critical objects do give you the benefit of accurate and detailed data in real time (who accessed what and when).

  • If auditing is carefully done on select objects for Access as well as Changes, it can be really useful to track down security issues in your Active Directory. But, gathering this data from all the domain controllers will require additional tools. If you enable audit, you must be clear on what to audit keeping in mind the security needs of your organization. You must not use auditing as a means to track down all accesses and changes to your Active Directory. Otherwise, you will end up with plenty of noise in your Security event logs and the size of your logs grow very quickly. This also places a significant load on your Domain controllers thereby affecting performance. Restricting your log size may help, but will require constant back up of your logs to prevent loss of data.

Active Directory Change Tracker tracks all changes to your AD without depending on the native audit capabilities of AD. You will need native auditing only if you need to find out who made the change and the most accurate time the change happened. You can combine native auditing with Active Directory Change Tracker to report this information and keep this archived in the tool’s Change History database.

In a nutshell, enable your AD auditing for critical changes in your AD and use Active Directory Change Tracker to scan your security event logs in all your domain controllers to extract detailed information on each changes made, including who made the change along with the most accurate time of change. If you are interested to track only what changed along with the new and old values, then you don’t have to enable AD auditing. You can simply rely on Active Directory Change Tracker to track all your changes.

 
     
   
Try and Buy
Download 15-day trial
Purchase Info
Datasheet
Buy Now *
   

* Starting at $499 

  Pricing Per domain 

  Perpetual license

  Unlimited Admin Users

 
 
 
 
solutions products support purchase resources company
SharePoint Migration SharePoint Product FAQ Product Purchase Downloads About Us
SharePoint Management Active Directory Software Upgrade Policy Partners& Resellers Case Studies Customers
Windows Audit & Reporting Windows Request License Key Custom Quote Request Product Tours Alliances
Application Audit & Reporting Exchange Software Registration   Sample Reports Testimonials
  IIS Contact Tech Support   Product Brochures Contact Us
    Software Feature Request   Online Help Site Map
        User Manuals Privacy Policy
        White Papers & Data Sheets  

Copyright © 1998-2012 Vyapin Software Systems (P) Ltd. All rights reserved.