I'm trying to setup Kaseya to monitor our clients AD so anytime a user is created we are notified of it. One of our old techs had this working at one point on our domain, but I can't find anything in Kaseya that shows the script or procedure that was setup by him. Does anyone have this setup that can guide me???
One way to accomplish this is to flip on "Audit account management" in the Local Security Policy. From there, all you need is an event set on the Security log for ID's 624 and 4720.
More info on auditting: technet.microsoft.com/.../cc737542(v=ws.10).aspx
Auditpol will give you the ability to change these settings from the command line: technet.microsoft.com/.../cc731451(v=ws.10).aspx
Do watch out for Security logging in Kaseya... it is the quickest way to blow up your database size if you aren't careful. Familiarize yourself with event log blacklisting before turning on Security log gathering: help.kaseya.com/.../index.asp