Scenarios that are discussed in this blog post include:
Scenario 1: Computers joined to the domain (names and description)
The following Event Id’s will be used in this procedure:
645 - A computer account was created.
646 - A computer account was changed.
647 - A computer account was deleted.
Note: Computer description cannot be reported on as it is not a parameter of the events.
Computer Accounts Created
Computer Accounts Deleted
Save the report created above as a different name, change the title and simply change the event id in step 6 above to 647 to report on deleted computer accounts.
Computer Accounts Changed
Scenario 2: User passwords expired
Event Id 535 (Logon failure. The password for the specified account has expired) will be used in this procedure.
Scenario 3: User accounts locked out
Event Id 644 (A user account was auto locked) will be used in this procedure.
Scenario 4: Group policy changes
Event Id 566 (A generic object operation took place) will be used in this procedure.