Alert: Changes to Domain Admins Membership

Source: Active Directory

Description: Get notifications on any membership changes of the Domain Admins group.

Purpose: Domain Admins group is critical to company's security and no one should be promoted to domain administrators without explicit control and supervision.

Creating an Alert

  1. Navigate to Active Directory / Alerts and click Create.
  2. Configure the alert as follows:

    FILTER

    SET TO

    Domain

    All domains

    Who

    Leave blank

    What

    All actions

    Object type

    group

    Attributes

    member

    Where

    %Domain Admins%

  3. On the Actions tab, provide an email.
  4. In the Save Alert dialog, provide an alert name and description. Make sure its status is set to "Enabled".

If a user is added or removed from the Domain Admins group, you will get a similar alert: