Info about Event logs (Active directory)

Ramanjaneyulu Butharaju 421 Reputation points
2020-08-25T07:42:07.46+00:00

Recently 3 of my Active directory admins are unable to login to AD server through RDP.

After we cross checked everything, we found these 3 users are added in one security group called "Deny RDP access" after i removed users from this group they are able to login now.

I just want to check is there any logs that can give me information about who added these 3 users into this "Deny RDP access" group ?

Is this security group(Deny RDP Access) is default or created one ??

If its created one, how to check who created it ?

Thanks,
Ram

Windows for business | Windows Client for IT Pros | User experience | Remote desktop services and terminal services
Windows for business | Windows Server | User experience | Other
0 comments No comments
{count} votes

Accepted answer
  1. Anonymous
    2020-08-25T09:40:03.317+00:00

    Hello,

    Thank you so much for posting here.

    To check the logs of new created security group and the member is added to this group and who creates this group, we could configure the below audit policy.

    20231-1.png

    And then check the Event Viewer to check the security events as shown below.

    20214-2.png

    20241-3.png

    Reference: https://learn.microsoft.com/en-us/windows/security/threat-protection/auditing/audit-security-group-management

    As per my research, this security group (Deny RDP Access) should be created one since I did not find this group in my AD environment. If it is created one, there might be other configuration of deny log on through RDS, such as this group policy setting as shown below. We could kindly have a check whether this policy is configured or not.

    Computer configuration\Policies\Windows Settings\Security Settings\Local Policies\User Rights Assignment

    20119-4.png

    For any question, please feel free to contact us.

    Best regards,
    Hannah Xiong

    0 comments No comments

2 additional answers

Sort by: Most helpful
  1. Ramanjaneyulu Butharaju 421 Reputation points
    2020-08-26T14:06:40.287+00:00

    HannahXiong-MSFT,

    Thank you so much. i will check your suggestions and get back to you.


  2. Ramanjaneyulu Butharaju 421 Reputation points
    2020-09-03T06:19:42.48+00:00

    hannahxiong,

    Unfortunately,
    Didn't find any event logs.

    anyways thanks. I learn some new things here..


Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.