Quest GPOADmin Integration
This appendix covers the following topics for GPOADmin integrations:
Requirements
Refer to the Release Notes for the list of minimum system requirements.
GPOADmin and Change Auditor integration process
Change Auditor records the following events:
A rename event for the new GPO.
Client components added to Change Auditor for Active Directory
•
• A built-in report that retrieves all Active Directory changes, including those initiated by GPOADmin. Running this report also displays the Initiator UserName and EventSource columns in the search results.Event Details pane
A Source field is available in the Event Details pane that displays the name of the application from which the change event was generated (such as, Change Auditor for Active Directory, Active Roles, or GPOADmin). In addition, for change events generated by GPOADmin or Active Roles, the name of the user account that initiated the change is displayed in parenthesis.
All Active Directory events including Active Roles/GPOADmin initiator built-in report
A built-in report is available that retrieves events for all Active Directory changes, including those initiated by GPOADmin and Active Roles. The search definition for this report also includes the initiator information (Initiator UserName and EventSource columns) in the search results.
To execute the built-in GPOADmin search:
2 Expand and select the Shared | Built-in | All Events folder to display the built-in searches available.
3 Locate the All Active Directory Events Including ActiveRoles/GPOADmin Initiator search and use one of the following methods to run the selected search:A new Search Results page appears populated with the audited events that met the search criteria, including the Initiator UserName and EventSource information.
Layout tab
Columns are added to the database to record the information retrieved from GPOADmin or Active Roles. These columns are not displayed by default on a Search Results page for most searches. However, using the Layout tab you can add the following information to all searches:
• EventSource - for all events, the name of the application from which the event was generated (i.e., Change Auditor for Active Directory, Active Roles, or GPOADmin).
• Initiator Mail - for events generated by GPOADmin or Active Roles, the email address of the user that initiated the change.
• Initiator SID - for events generated by GPOADmin or Active Roles, the SID of the user that initiated the change.
• Initiator UserName - for events generated by GPOADmin or Active Roles, the name of the user that initiated the change.To add new columns to the search results:
2 Locate the new columns (EventSource, Initiator Mail, Initiator SID, and/or Initiator UserName) in the Unselected Columns table.
3You can also drag a column to the Selected Columns table.
You can also drag columns within this table to define the order.
Who tab
When using the Who tab to retrieve change events initiated by a specific user, changes initiated by GPOADmin will not automatically be included in the search. A check is available in the Who tab which instructs Change Auditor for Active Directory to retrieve all change events initiated by the specified user, including those made through GPOADmin.
To include GPOADmin initiated events:
3 Click New to enable the Search Properties tabs.
4 On the Who tab, click Add to add an active user, computer or group to the ‘who’ list.Once you have located the directory object to be included, select it and click Add.
Repeat this step to include each additional directory object.
6 After selecting one or more directory objects, click Select to save your selection and close the dialog.
7 Back on the Who tab, select the Include Event Source Initiator check box.
In addition, when this check box is selected the Initiator UserName column is added to the Search Results grid for this search. For events initiated by GPOADmin, this column contains the user account that was logged into the GPOADmin console.
Email tags
See the Change Auditor User Guide for more information on how to configure and enable email notifications and customize email content.