Is there any event id to know if the computer is on DC or not?

Subhan Tanriverdiyev 0 Reputation points
2024-06-29T01:22:59.0766667+00:00

In big companies sometimes the computers may not be in the domain. Can we find it based on coming logs in SIEM?

Windows Server
Windows Server
A family of Microsoft server operating systems that support enterprise-level management, data storage, applications, and communications.
13,022 questions
0 comments No comments
{count} votes

1 answer

Sort by: Most helpful
  1. Hania Lian 15,016 Reputation points Microsoft Vendor
    2024-07-01T02:09:12.5566667+00:00

    Hello,

    You can check for the following event IDs:

    Event ID 3260: Indicates a computer has joined a domain.

    Event ID 3261: Indicates a computer has left a domain to join a workgroup.

    Additionally, for domain controllers (DC), you can look for:

    Event ID 4741: Shows details about new computer accounts created, including who created it.

    Event ID 4740: Indicates the source of account lockouts in Active Directory.

    Best Regards,

    Hania Lian

    ============================================

    If the Answer is helpful, please click "Accept Answer" and upvote it.

    0 comments No comments

Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.