Event ID for unconstrained delegation enumeration

Jasmine Drossa 1 Reputation point
2022-09-29T10:11:56.637+00:00

Hi,
Similar to 4799, are there any event IDs generated to monitor the following activities that is performed on the domain/workstation/DC?

Get-AdComputer -Filter {TrustedForDelegation -eq $True}
Get-AdUser
Get-AdComputer

Or Maybe when view the Computer Properties from the "Active Directory Computers & Users"?
Are there any logs recorded?

I checked 4662 either but couldnt find any related logs.

Regards,

Windows Server
Windows Server
A family of Microsoft server operating systems that support enterprise-level management, data storage, applications, and communications.
12,214 questions
Active Directory
Active Directory
A set of directory-based technologies included in Windows Server.
5,947 questions
Windows Server Security
Windows Server Security
Windows Server: A family of Microsoft server operating systems that support enterprise-level management, data storage, applications, and communications.Security: The precautions taken to guard against crime, attack, sabotage, espionage, or another threat.
1,733 questions
0 comments No comments
{count} votes

1 answer

Sort by: Most helpful
  1. Limitless Technology 43,971 Reputation points
    2022-09-30T09:03:01.857+00:00

    Hello

    Thank you for your question and reaching out. I can understand you are having query related to Event logs.

    You need to enable Advanced Audit log policy for AD object created\modified\deleted\accessed

    Create a new GPO.
    Click Edit and navigate to Computer Configuration > Policies > Windows Settings > Security Settings > Advanced Audit Policy Configuration > Audit Policies. Under Audit Policies, you'll find specific settings for Logon/logoff and Account Logon.
    Logon/logoff:
    Audit Logon > Define > Success and Failure.
    Audit Logoff > Define > Success.
    Audit Other Logon/Logoff Events > Define > Success.
    Account Logon:
    Audit Kerberos Authentication Service > Define > Success and Failure.

    ------------------------------------------------------------------------------------------------------------------------------------------

    --If the reply is helpful, please Upvote and Accept as answer--

    1 person found this answer helpful.
    0 comments No comments