For the best web experience, please use IE11+, Chrome, Firefox, or Safari

Change Auditor

Real-time security and IT auditing for your Microsoft Windows environment. Change reporting and access logging for Active Directory (AD) and enterprise applications is cumbersome, time-consuming and, in some cases, impossible using native IT auditing tools. This often results in data breaches and insider threats that can go undetected without protections in place. Fortunately, there's Change Auditor, real-time IT auditing, in-depth forensics and comprehensive security monitoring on all key user and administrator changes for Microsoft Windows environments.

Change Auditor 7.1 – New Features 10:32
With Change Auditor, you get complete, real-time IT auditing, in-depth forensics and security threat monitoring on all key configuration, user and administrator changes for Microsoft Active Directory, Azure AD, Exchange, Office 365, file servers and more. Change Auditor also tracks detailed user activity for logons, authentications and other key services across enterprises to enhance threat detection and security monitoring. A central console eliminates the need and complexity for multiple IT audit solutions.

Hybrid environment auditing

Get a single, correlated view across your hybrid Microsoft environments, with visibility of all changes whether on-prem or in the cloud.

Security threat monitoring

Audit and block exploits such as credential theft and AD database copies, and identify applications using authentications over insecure protocols.

Golden Ticket detection

Detect and alert on common Kerberos authentication vulnerabilities used during Golden Ticket / Pass-the-ticket attacks.

Object protection

Protect against changes to critical data within AD, Exchange and Windows file servers, including privileged groups, GPOs and sensitive mailboxes.

Normalized 5W audit details

Translate cryptic native logs into a simple, normalized format highlighting the who, what, when, where and workstation details and before and after values.

Real-time alerts on the move

Send critical change and pattern alerts to email and mobile devices to prompt immediate action, even while you're not on site.

SIEM integration

Integrate with SIEM solutions to forward Change Auditor events to Splunk, ArcSight, QRadar or any platform supporting Syslog.

Auditor-ready reporting

Generate comprehensive reports to support regulatory compliance mandates for GDPR, PCI DSS, HIPAA, SOX, FISMA / NIST, GLBA and more.

On Demand Audit Hybrid Suite for Office 365

Overview of On Demand Audit 07:25
With just a few clicks, you can pair Change Auditor for Active Directory and Change Auditor for Logon Activity with On Demand Audit to get a single, hosted view of all changes made across AD, Azure AD, Exchange Online, SharePoint Online, OneDrive for Business and Teams. On Demand Audit proactively highlights security vulnerabilities and anomalous activity, and accelerates incident investigations through responsive search and interactive data visualizations.

Features

Account lockout

Capture the originating IP address/workstation name for account lockout events to simplify troubleshooting.

Related searches

Provide instant, one-click access to all information on the change you're viewing and all related events, such as what other changes came from specific users and workstations, eliminating additional guesswork and unknown security concerns.

Superior auditing engine

Remove auditing limitations and capture change information without the need for native audit logs, resulting in faster results and significant savings of storage resources.

Security threat timelines

View, highlight and filter change events and discover their relation to other security events in chronological order across your Microsoft environment for better forensic analysis and security incident response.

Improved security insights

Correlate disparate IT data from numerous systems and devices into IT Security Search, an interactive search engine for fast security incident response and forensic analysis. Include user entitlements and activity, event trends, suspicious patterns and more with rich visualizations and event timelines.

Quest InTrust integration

Integrate with Quest InTrust for 20:1 compressed event storage and centralized native or third-party log collection, parsing and analysis with alerting and automated response actions to suspicious events such as known ransomware attacks or fishy PowerShell commands.

Platforms

Learn about Change Auditor for Active Directory 04:07

Learn about Change Auditor for Active Directory

Active Directory

Change Auditor for Active Directory and Change Auditor for Logon Activity detect and alert on changes to critical objects in Microsoft Active Directory and Azure AD with a single, correlated view across your hybrid AD environment. Track Kerberos, NTLM and ADFS authentications to help proactively identify vulnerabilities.

Product Demo: Learn about On Demand Audit 07:25

Product Demo: Learn about On Demand Audit

Azure AD and Office 365

With just a few clicks, you can pair Change Auditor for Active Directory and On Demand Audit to get a single, hosted view of all changes made across AD, Azure AD, Exchange Online, SharePoint Online and OneDrive for Business.

Learn about Change Auditor for Exchange 04:02

Learn about Change Auditor for Exchange

Exchange

Change Auditor for Exchange simplifies the Exchange auditing process. Track, audit, report and alert on Microsoft Exchange on-premises and Exchange Online changes in real time within a single, correlated view.

Product Demo: Change Auditor for Windows File Servers 03:52

Product Demo: Change Auditor for Windows File Servers

Windows Server

Change Auditor for Windows File Servers helps you control and audit changes to Microsoft Windows Server efficiently and cost-effectively. Proactively track, audit, report on and alerts on vital changes, including user and administrator accounts, in real time and without the overhead of native auditing.

Product Demo: Change Auditor for SQL Server 04:06

Product Demo: Change Auditor for SQL Server

SQL Server

Change Auditor for SQL Server makes database auditing of Microsoft SQL Server easy and secure. It tracks, audits, reports on and alerts on changes in real time, translating events into simple terms and eliminating the time and complexity required for auditing.

Product Demo: Change Auditor for NetApp 05:04

Product Demo: Change Auditor for NetApp

Network-attached storage

Ensure the security, compliance and control of files, folders and shares by tracking, auditing, reporting and alerting on all changes in real time. With Change Auditor for NetApp, EMC or FluidFS, you can report on and analyze events and changes without the complexity and time required with native auditing.

Overview of Change Auditor for SharePoint 03:26

SharePoint and OneDrive for Business

Change Auditor for SharePoint enables faster, easier and more secure SharePoint, SharePoint Online and OneDrive for Business auditing. It translates events into simple terms, stores data in one centralized and secure database and, in real time, tracks, audits, reports on and alerts on critical changes to:

  • SharePoint farms, servers, sites, users, permissions and more
  • File and folder activity as well as sensitive data moving in and out of OneDrive for Business
How to audit changes to Skype in Change Auditor for Skype for Business 04:18

Skype for Business

Change Auditor for Skype for Business provides enterprise-wide visibility that allows you to see how Skype for Business is configured and enforced, so you can take a proactive management approach. Get alerts and reports on administrator activity, security and configuration changes in real time.

VMware

VMware

Change Auditor for VMware vCenter helps you ensure the security, compliance and control of event activity, and the security of VMware vCenter Server. It manages, audits, reports on and provides alerts on all changes to the platform in real time, making VMware monitoring easy.

Featured Products

Change Auditor for Active Directory

Ensure security, compliance and control of AD and Azure AD.

Download Free Trial

Change Auditor for Logon Activity

Alert and report on AD logon and logoffs and Azure AD sign-in activity

Download Free Trial

Change Auditor for Active Directory Queries

Solve migration and performance issues by analyzing Active Directory queries.

Download Free Trial

On Demand Audit

Search and investigate changes made on prem or in the cloud from a single, hosted dashboard.

Try Online

Change Auditor for Exchange

Document all critical group, mailbox and public/private changes to Exchange

Download Free Trial

Change Auditor for Windows File Servers

Track, audit and receive reports on all Windows File Server real-time system changes

Download Free Trial
Show more

Large Retail Chain

Change Auditor object protection is a lifesaver. I have it set up to prevent changes to the ACLs on certain directories on our file servers, as well as to protect all administrative accounts. We’ve had pen testers come in and be very surprised that they could not get past the Change Auditor object protection

Enterprise Administrator, Large Retail Chain Read Case Study

AFV Beltrame Group

With Change Auditor, we achieved our goal of gaining complete and centralized visibility of security audit operations across the entire Group— including not just our on-premises Windows file servers and domain controllers but also our Office 365 services, such as mail, SharePoint Online and OneDrive for Business

Mirco Destro CIO and IT Manager, AFV Beltrame Group Read Case Study

Region Halland

Previously, investigating an issue could easily take an hour. Change Auditor cuts that time to just 5–10 minutes.

Dennis Persson IT Systems Technician, Region Halland Read Case Study

Stevie Awards 2018 People’s Choice winner

In the 2018 Stevie Award’s People Choice awards, Change Auditor was voted best software and also won a Silver Stevie for best new product of 2018

Get Started Now

Experience real-time Microsoft Windows security & IT auditing.