Change Auditor 7.4 - Installation Guide

Installation Overview Install Change Auditor Add Users to Change Auditor Security Groups Connecting to the Clients Deploy Change Auditor Agents Upgrade Change Auditor Installation Notes and Best Practices Deployment Options Workstation Agent Deployment Agent Comparison Install an agent to audit ADAM (AD LDS) on workgroup servers Windows Installer Command Line Options

Deployment Options

Change Auditor can be configured to audit and report on one or many Active Directory forests to facilitate searching for compliance audit data. There are two deployment options available to you:

The following section outlines the support, requirements, recommendations and steps for deploying agents, and example deployments for these deployment options:

Multi-forest deployment


The following must be in place for multi-forest deployments:

To connect to coordinators in other forests, users must be added to either the ‘ChangeAuditor Administrators — <InstallationName>’ OR ‘ChangeAuditor Operators — <InstallationName>’ in the forest where the coordinator is joined.

Example deployment scenario

The following diagram shows two separate forests where Change Auditor will be deployed. Forest A is deployed first and the Forest B is added.

Forest A installation

Forest B installation

Quest recommends that the same database access account used in the first forest is also used in the second forest. If a different user account for database access is used in the second coordinator's installation, the following permissions must be granted before the installation is started:
db_owner database role on the Change Auditor database
dbcreator server role
