Operating Systems Windows Server 2008
Category Account Management
Subcategory Application Group Management
Type Success
Legacy Events 690
The user in Subject: removed Member: from the application group identified in Group:.
Application groups are part of Windows's role based access control for applications and are maintained in the Authorization Manager MMC snap-in.
This event does not report the common name (cn) of the group you are accustomed to seeing in Authorization Manager where application groups are maintained. This is really bad because the account name reported in this event isn't displayed anywhere in Authorization Manager. To find out the common name of the group look for the Directory Service Changes events immediately following this event which do report the common name.
Subscribe to:
Post Comments (Atom)
0 comments:
Post a Comment