Real-Time Auditing and Change Control for Active Directory

Auditor for Active Directory helps IT organizations meet PCI, SOX, HIPAA and other compliance requirements by auditing and alerting on Active Directory configuration changes in real time. Pinpoint changes that introduce security risks, jeopardize compliance, or impact operations via the solution’s real-time tracking of:

The solution’s centralized database enables both auditing and recovery, delivering a broader set of capabilities than native AD auditing – without the operational impacts.

Quote Image

"... we’ve seen a 50% decrease in time spent manually tracking down who made changes to critical areas like group policy ..."

SVP, Information Tech Services, Columbia Bank

Real-Time, Centralized Active Directory Auditing and Alerting

Audit, alert and report on all changes made in Active Directory in real time without relying on difficult and cumbersome native event logs. Centralized, real-time auditing – including before and after values and simplified event translation – helps to quickly identify changes that can impact the security of the environment.

Integration of Audit and Recovery

Auditor for Active Directory is part of a suite of auditing and recovery solutions that track and alert to changes across the Windows environment – from Exchange, to Windows File Servers, SQL Server and NetApp. A web-based console acts as a single pane of glass helping administrators more easily manage their deployment and quickly meet compliance needs.

No Requirement for Native Auditing

Auditor for Active Directory does not require any GPO changes or native System Access Control Lists to be managed or defined. IT can leverage native auditing using Microsoft ACS along with Auditor for Active Directory to narrow the search for which audit log contains the needed information, making the process to find and remediate a change much quicker than using native auditing alone.

Common Criteria Certified

Common Criteria is an internationally recognized set of guidelines created to insure a high and consistent standard for evaluating information security products. You can have confidence in the security of the products that have earned this certification through extensive independent lab evaluations, and avoid the cost and complexity of additional testing. Auditor for Active Directory has earned Common Criteria Certification under an Evaluation Assurance Level (EAL)2+.

Benefits of Auditor for Active Directory

Active Directory Auditing

Reduce risk: Pinpoint changes that introduce security risks, jeopardize compliance, or reduce operational efficiency.

Know who has access to what: Monitor access to mission-critical and sensitive IT assets.

Ensure accountability: Track the “who, what, when and where” for every Active Directory change.

Compare before and after: See old and new values for every change, including host name and originator IP address.

Audit event translation: Enable less technical users to understand what activity has occurred while still maintaining the advanced details that administrators require.

Integrate with native management tools: Gain single-click access to item and user histories via integration with native management tools such as Active Directory Users and Computers, Sites and Services, ADSI Edit and others.

Enhanced auditing for Windows: Any change to Windows Group Policy is captured with pre- and post-values, providing complete least privilege enforcement and policy auditing in a single solution.

Audit changes made to cells in Identity Services: Audit attributes in default and named cells.

Track backlinks: Audit changes that have a direct impact on an object, providing greater visibility over all changes and their downstream impacts.

Customize alerting: Design HTML templates or plain text email notifications, and simplify the appending, replacing or removing of recipients to alert notifications.

FSMO auditing: Any changes to FMSO roles are audited and can be alerted on.

Deployment and Scalability

Speed deployment: Ensure trouble-free deployments with a centralized database, agent and management console.

Cover your entire organization: Audit environments with millions of users and thousands of servers.

Simplify administration: Unite products in the suite through a web console which serves as a dashboard that enables admins and other users to perform management and enforce policy across their Auditing and Security Suite deployment.

Intelligent search: Allow administrators or auditors to filter what they are looking for based on a user-friendly description of the change activity.

User preferences: Increase usability and enable a consistent experience for users with more than a dozen customization preferences – from colorblind options to column order.

RESTful Web Service: Automate agent deployment, restore deleted objects or roll back unwanted changes to existing objects.

Reporting and Compliance

Centralize all audits: Access all audit data via a single database, even for multiple AD forests.

Customize to your needs: Leverage intuitive wizards to quickly build custom reports and convert any view into a report.

Automate reporting: Take advantage of expanded delivery options and formats via SQL Server Reporting Services

Confirm compliance: Provide access and change histories for compliance with SOX, PCI, HIPAA and other mandates.

No Native Auditing

Free yourself from native event logs: Conduct audits without managing SACLs or changing GPOs.

Ease native auditing (when required): When Microsoft ACS auditing is required, Auditor can identify which native logs contain needed information.

Integrated Continuous Recovery

Maintain business continuity: Avoid productivity and revenue losses caused by disasters or accidental deletions.

Recover any state: Rely on continuous backups to quickly return to any previous state.

Minimize disruption: Recover a full tree, a portion of the directory, selected objects, or individual attributes.

One click recovery: Recover deleted objects from the audit event, speeding time to resolution.

Rollback queue: Create a search for items and add to a queue in a single, simple step.