0

In my environment, someone renamed the "Group name" of an active directory global security group. (I refer here to the attribute sAMAccountName, not the display name)

I'd like to know who did so and I can't manage to get it done by PowerShell using Get-WinEvent. I don't know if some of you already managed to get it done, but on my side I struggle to identify the condition required to do so.

Any idea is welcomed !

Thanks in advance :)

  • 1
    That information should be available in the security log on the domain controller where the rename event was processed (caveats: Auditing must be enabled, etc.). This is not a stackoverflow question, though. – Bill_Stewart Sep 08 '18 at 13:39
  • Questions on professional server- or networking-related infrastructure administration are off-topic for Stack Overflow unless they directly involve programming or programming tools. You may be able to get help on `Server Fault`. – Am_I_Helpful Sep 09 '18 at 05:10

0 Answers0