How to find who changed a users' Manager in AD

Moore, Eric 21 Reputation points
2025-04-22T20:07:47.8633333+00:00

The attribute "manager" was recently altered for a member of our C-Suite recently. Needless to say the change was unauthorised, so we're trying to find who made what we hope is a genuine mistake ;). We have advanced audit policies configured, and Account Management Audit is enabled. We see eventCode 4738 frequently. However, this audit policy does not appear to cover amendments to the field "manager". We have tested some controlled cases today and nothing.

What should be set to capture changes to this field?

AD running on W2019 in Forest and Domain 2012 Functional Mode.

Windows Server 2019
Windows Server 2019
A Microsoft server operating system that supports enterprise-level management updated to data storage.
4,063 questions
0 comments No comments
{count} votes

Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.