立即与支持人员聊天
与支持团队交流

Change Auditor for Active Directory 7.3 - Event Reference Guide

Domain Configuration

Allowed DNS Suffix List Changed for Domain

Created when a new value is added to or removed from the list of allowed DNS suffixes for a domain.

Medium

DACL Changed on AdminSDHolder Object

Created when the DACL is changed for an object located at CN=AdminSDHolder,CN=System, DC=<Domain Name>.

High

DACL Changed on Domain Object

Created when the DACL is changed on a domain object.

High

Default Quota for Partition Changed

Created when the default object quota for the Configuration NC, a domain NC, or an application partition is changed.

Medium

Domain Controller Added to Domain

Created when a new domain controller is promoted into the domain.

Medium

Domain Controller Removed from Domain

Created when a domain controller is demoted from the domain.

Medium

Domain Controller Renamed

Created when a domain controller is renamed.

Medium

Domain Functional Level Changed

Created when the domain functional level is changed.

Medium

Domain Group Policy Order Changed

Created when the list of group policies linked to a domain is re-ordered.

Medium

Guest Account Disabled

Created when the Guest account is disabled in a domain.

Medium

Guest Account Enabled

Created when the Guest account is enabled in a domain.

Medium

Infrastructure FSMO Role Owner Moved

Created when the infrastructure FSMO role owner is changed from one DC to another.

High

Inheritance Setting Changed on AdminSDHolder Object

Created when the inheritance setting of an AdminSDHolder object is changed.

High

Object Quota Added

Created when a new object quota is added to an NC.

Medium

Object Quota Removed

Created when an object quota is removed from an NC.

Medium

PDC FSMO Role Owner Moved

Created when the PDC FSMO role owner is changed from one DC to another.

High

Quota Security Principal Changed

Created when the security principal for an existing quota is changed.

Medium

Quota Value Changed

Created when the quota value for an existing quota is changed.

Medium

Read-Only Domain Controller Added to Domain

Created when a Read-Only Domain Controller is added to a domain.

Medium

Read-Only Domain Controller Removed from Domain

Created when a Read-Only Domain Controller is demoted.

Medium

Read-Only Domain Controller Renamed

Created when a Read-Only Domain Controller is renamed.

Medium

RID FSMO Role Owner Moved

Created when the RID FSMO role owner is changed from one DC to another.

High

Tombstone Quota Factor for Partition Changed

Created when the quota factor for tombstone objects is changed for the Configuration NC, a domain NC, or an application partition.

Medium

Trust Added

Created when a Trust is created between 2 domains.

Medium

Trust Removed

Created when a Trust is removed.

High

Dynamic Access Control

NOTE: Dynamic Access Control is available in Windows® Server 2012; therefore, the events in this facility do not apply to earlier versions of Windows Server.

Central Access Policy Created

Created when a Central Access Policy is created.

Medium

Central Access Policy Description Changed

Created when the description of a Central Access policy is changed.

Medium

Central Access Policy Deleted

Created when a Central Access Policy is deleted.

Medium

Central Access Policy Permission Changed

Created when the permission of a Central Access Policy is changed.

High

Central Access Policy Rule Added

Created when a rule is added to a Central Access Policy.

Medium

Central Access Policy Rule Changed

Created when a rule for a Central Access Policy is changed.

Medium

Central Access Policy Rule Removed

Created when a rule is removed from a Central Access Policy.

Medium

Central Access Rule Created

Created when a central access rule is created.

Medium

Central Access Rule Description Changed

Created when the description of a central access rule is changed.

Medium

Central Access Rule Deleted

Created when a central access rule is deleted.

Medium

Central Access Rule Effective Permission Changed

Created when the effective permission of a central access rule is changed.

High

Central Access Rule Permission Changed

Created when the permission of a central access rule is changed.

High

Central Access Rule Proposed Permission Changed

Created when the proposed permission of a central access rule is changed.

High

Central Access Rule Target Resource Changed

Created when the target resource of a central access rule is changed.

Medium

Claim Type AD Attribute Changed

Created when an AD attribute for a claim type is changed.

Medium

Claim Type Class Added

Created when a claim type class is added.

Medium

Claim Type Class Changed

Created when a claim type class is changed.

Medium

Claim Type Class Removed

Created when a claim type class is removed.

Medium

Claim Type Created

Created when a claim type is created.

Medium

Claim Type Deleted

Created when a claim type is deleted.

Medium

Claim Type Description Changed

Created when the description of a claim type is changed.

Medium

Claim Type Disabled

Created when a claim type is disabled.

Medium

Claim Type Display Name Changed

Created when the display name of a claim type is changed.

Medium

Claim Type Enabled

Created when a claim type is enabled.

Medium

Claim Type Permission Changed

Created when the permission of a claim type is changed.

High

Claim Type Suggested Values Changed

Created when the suggested values of a claim type are changed.

Medium

Reference Resource Property Created

Created when a reference resource property is created.

Medium

Reference Resource Property Deleted

Created when a reference resource property is deleted.

Medium

Reference Resource Property Description Changed

Created when the description of a reference resource property is changed.

Medium

Reference Resource Property Disabled

Created when a reference resource property is disabled.

Medium

Reference Resource Property Display Name Changed

Created when the display name of a reference resource property is changed.

Medium

Reference Resource Property Enabled

Created when a reference resource policy is enabled.

Medium

Reference Resource Property Permission Changed

Created when the permission of a reference resource policy is changed.

High

Resource Property Created

Created when a resource property is created.

Medium

Resource Property Deleted

Created when a resource property is deleted.

Medium

Resource Property Description Changed

Created when the description for a resource property is changed.

Medium

Resource Property Disabled

Created when a resource property is disabled.

Medium

Resource Property Display Name Changed

Created when the display name for a resource property is changed.

Medium

Resource Property Enabled

Created when a resource property is enabled.

Medium

Resource Property Permission Changed

Created when the permission for a resource property is changed.

High

Resource Property Suggested Values Changed

Created when the suggested values for a resource property are changed.

Medium

Resource Property List Created

Created when a resource property list is created.

Medium

Resource Property List Deleted

Created when a resource property list is deleted.

Medium

Resource Property List Description Changed

Created when the description of a resource property list is changed.

Medium

Resource Property List Member Added

Created when a member is added to a resource property list.

Medium

Resource Property List Member Changed

Created when a member of a resource property list is changed.

Medium

Resource Property List Member Removed

Created when a member is removed from a resource property list.

Medium

Resource Property List Permission Changed

Created when the permission of a resource property list is changed.

High

Forest Configuration

Alternate UPN Suffix Added to Enterprise

Created when an entry is added to the list of alternate UPN suffixes available for user names.

Medium

Alternate UPN Suffix Removed from Enterprise

Created when an entry is removed from the list of alternate UPN suffixes available for user names.

Medium

Cross-forest Trust Added

Created when a trust is created between 2 forests.

Medium

Cross-forest Trust Removed

Created when a trust is removed between 2 forests.

High

Domain Added

Created when a domain is added to the partitions container.

High

Domain FSMO Role Owner Moved

Created when the domain naming FSMO role owner is changed from one DC to another.

High

Domain Removed

Created when a domain is removed from the partitions container.

High

Extended Access Right Added

Created when a new extended access right object is added to the system.

Medium

Extended Access Right Removed

Created when an extended access right object is removed from the system.

Medium

Forest Functional Level Changed

Created when the forest functional level is changed.

High

GC Added

Created when a domain controller is promoted from a non-GC to a GC.

Medium

GC Removed

Created when a domain controller is demoted from a GC to a non-GC.

High

Member Added to Critical Enterprise Group

Created when a new member is added to one of the critical enterprise groups. Critical enterprise groups include:

High

Member Removed from Critical Enterprise Group

Created when a new member is removed from one of the critical enterprise groups. Critical enterprise groups include:

High

Nested Member Added to Critical Enterprise Group

Created when a member is added to a nested group in a critical enterprise group.

High

Nested Member Removed from Critical Enterprise Group

Created when a member is removed from a nested group in a critical enterprise group.

Medium

Query Policy Added

Created when a new domain controller query policy is added.

Low

Query Policy Removed

Created when a domain controller query policy object is removed.

Low

Schema FSMO Role Owner Moved

Created when the schema FSMO role owner is changed from one DC to another.

High

Site Added

Created when a new site is added to the forest.

Medium

Site Link Added

Created when a site link is added to either the IP or SMTP containers.

Medium

Site Link Bridge Added

Created when a site link bridge is added to either the IP or SMTP containers.

Medium

Site Link Bridge Removed

Created when a site link bridge is removed from either the IP or SMTP containers.

High

Site Link Removed

Created when a site link is removed from either the IP or SMTP containers.

High

Site Removed

Created when a site is removed from the forest.

High

Site Renamed

Created when an existing site is renamed.

Medium

Subnet Added

Created when a new subnet is added.

Medium

Subnet Removed

Created when a subnet is removed.

High

FRS Service

FRS Access Check Changed

Created when an FRS access check is changed.

Low

FRS Directory Exclusion Filter List Changed on Domain Controller

Created when the FRS directory exclusion filter list on a domain controller is changed.

Low

FRS Directory Exclusion Filter List Changed on Replica Set

Created when the FRS directory exclusion filter list on a Replica Set is changed.

Low

FRS File Exclusion Filter List Changed for Replica Set

Created when the FRS file exclusion filter list on a Replica Set is changed.

Low

FRS File Exclusion Filter List Changed on Domain Controller

Created when the FRS file exclusion filter list on a Domain controller is changed.

Low

FRS Mutual Authentication Setting Changed

Created when the FRS mutual authentication is changed.

Low

FRS RPC TCP/IP Port Assignment Changed

Created when the FRS TCP/IP port assignment is changed.

Low

FRS Staging Space Limit Changed

Created when the FRS Staging space limit is changed.

Low

FRS Working Directory Changed

Created when the FRS working directory is changed.

Low

相关文档

The document was helpful.

选择评级

I easily found the information I needed.

选择评级