Howdie!
Am 26.05.2010 16:24, schrieb RC:
> User account create/delete
> Account Lockouts
> Computer obj join and deletes
> users/groups/computers being moved from OU's
> who is logging into domain controllers.
> System Reboots
> Group Policy changes
Those can be retrieved with normal AD auditing -- you simply need a
"collector" that combs through the event logs once you have auditing
setup corretly.
If you want SCOM, that's okay it is a solid product -- but there are
other tools that can do that as well. I would look into what SCOM gets
you what you could use in addition.
Cheers,
Florian
|