Active Identity Guardianby Kinleong Consulting

Active Directory auditing

Know who changed what in Active Directory

Turn fragmented Windows events into a searchable Active Directory audit trail with the actor, source, affected object and full before-and-after values.

Users · Groups · Computers · Organisational Units · Group Policy · Privileged activity

Active Directory change auditing without raw-event investigation

Windows records directory activity across domain controllers, but the security meaning is often buried inside event IDs and attribute data. When an administrator needs to explain a privileged group change, password reset or GPO modification, searching each server individually creates delay and inconsistent evidence.

Active Identity Guardian collects and enriches Active Directory events so the team can search changes by actor, target, time, source workstation, IP address, object type and risk. Each supported modification can show the value before the change and the value afterwards.

Complete change context

See the account responsible, the affected directory object, the originating workstation or IP and the exact time.

Before and after values

Understand not only that an object changed, but which attribute changed and how its value was modified.

Risk-focused investigation

Prioritise privileged, off-hours and security-relevant changes rather than treating every audit event equally.

Changes that security and IT teams commonly audit

Users created, modified, disabled or deleted
Password resets and account-control changes
Members added to or removed from privileged groups
Computer and service account changes
Organisational Unit moves and modifications
Group Policy creation, deletion and updates
Changes performed by privileged administrators
Activity from unusual sources or outside normal hours

Search, live tail and reporting

Faceted search allows analysts to move quickly from a user or object to the related activity. Live-tail views expose new events as they arrive, while built-in and saved reports provide repeatable evidence for internal governance, external audit and incident investigation.

Auditing is more useful when connected to posture

A change can create a new exposure even when the event itself appears legitimate. Active Identity Guardian connects audit activity with posture scoring and exposure management so teams can see whether a change increased risk and which identities are affected.

Hybrid auditing across AD and Entra ID

Organisations using both Active Directory and Microsoft Entra ID need to investigate identity activity across two control planes. Active Identity Guardian provides a shared interface for supported on-premises and cloud directory changes, while retaining separate AD and Entra posture views.

Investigate a real directory change

See how Active Identity Guardian captures and explains changes from your own Active Directory environment.

Book a live demo