So we have an issue. We have an admin somewhere removing people from security groups they need to be a part of. I'm new to this division and they do not have any kind of active compliance in place. Its an on premise security group and I have not been given rights to see the audit logs within the Web interface for exchange, only the O365 Exchange which does not pull audit logs for On-Prem groups.
I tried to view the EventLogs on the DC but whenever I go to filter the list the MMC plugin crashes.
How can I go about finding out who is removing users from their security groups? The IT Director has tasked me with gathering this information. I tried to view Event Logs by ID through powershell but its not providing the full details beyond
Index Time Entry Type, Source, and InstanceID Message.
Powershell is not my strong suit and the division I...