Password times changed and it's log
only date of last password change saved in active directory. need enable auditing of password change events, , periodically scan security event logs appropriate events. per article, eventcode attempted password changes 4723:
http://support.microsoft.com/kb/947226
since recent events maintained in logs (they overwrite themselves), need scan , retain events want. might able use script script gallery:
http://gallery.technet.microsoft.com/709315b1-3417-4b77-8b1f-fa9fc0e10b0e
richard mueller - mvp directory services
Windows Server > Windows Server General Forum
Comments
Post a Comment