TopicActive Directory →
One member was added to a local security group.
Source of event
Microsoft-Windows-Security-Auditing — Security category.
Possible causes
- Adding,a local administrator
- Applicative delegation
- Unauthorised amendment
Verifications to be carried out
- Identify target group
- Control the user added….
- Check author and justification….
Useful orders….
Get-WinEvent -FilterHashtable @{LogName='Security'; Id=4732} -MaxEvents 30
To be retained….
An Event ID must always be interpreted with its source, its full message, its timing and the context of the system. The same number may exist in several providers of events.