SIEM, Vulnerability Scanning, Server Monitoring and Compliance Training for IT Professionals
Table of Contents

Group Policy Object (GPO) Auditing

GPO Auditing is the process of scanning Security Event Log entries for Event IDs 5136, 5137, 5138, 5139 and 5141 then either generating a report of changes or triggering real-time alerts.

GPO Auditing Event IDs

Event IDDescription
5136A directory service object was modified.
5137A directory service object was created.
5138A directory service object was undeleted.
5139A directory service object was moved.
5141A directory service object was deleted.

How to Generate a GPO Audit Report

Corner Bowl Server Manager includes 2 built-in Active Directory GPO Audit Reports.

ReportDescriptionLocation
Audit Directory Service ChangesA simple auto-generated report that scans for Event IDs: 5136, 5137, 5138, 5139, 5141.Sample Reports / Event Logs / Advanced Audit Policy / DS Access.
Audit Directory Service Changes (Correlation ID)A report that scans for Event IDs: 5136, 5137, 5138, 5139, 5141 then uses a regular expression to parse out the Correlation ID value.Sample Reports / Event Logs / Security Reports.

How to Real-Time Monitor GPO Changes

Corner Bowl Server Manager includes 1 built-in Real-Time Active Directory GPO Changes Template.

TemplateDescriptionLocation
Real-Time Directory Service Object ChangesWatches for Event IDs: 5136, 5137, 5138, 5139, 5141 then triggers a desktop and email alert.Sample Templates / Real-Time Monitors
Important
This template is marked as an Agent Template. To utilize Remote WMI instead, clear Agent Template Enabled checkbox found in the Template's Agent Tab.

Related Topics

Reports

Templates