Microsoft does have in-built features and tools to monitor and audit AD environments. In this section, we are going to review these features and tools.
Auditing and monitoring AD using in-built Windows tools and techniques
Windows Event Viewer
As an engineer, I am sure you are well aware of Windows Event Viewer. It is a built-in tool that can be used to view and filter event logs on a local or remote computer. Events in there are generated by the operating system, services, server roles, and applications. This is the most commonly used tool in Windows systems for auditing and troubleshooting purposes.
We also can write custom events to event logs. This is useful if you plan to run a script or action based on a particular event...