<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" href="https://www.quest.com/community/cfs-file/__key/system/syndication/rss.xsl" media="screen"?><rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:wfw="http://wellformedweb.org/CommentAPI/"><channel><title>Change Auditor</title><link>https://www.quest.com/community/change-auditor/</link><description /><dc:language>en-US</dc:language><generator>Telligent Community 13</generator><item><title>Forum Post: How can I search for changes in extensionAttributes?</title><link>https://www.quest.com/community/change-auditor/f/forum/37306/how-can-i-search-for-changes-in-extensionattributes</link><pubDate>Mon, 20 Apr 2026 15:38:00 GMT</pubDate><guid isPermaLink="false">5f2f4fa7-ebc7-4803-900c-42d427844a5e:45c96220-c9f2-4f56-a288-9a464d5aedb1</guid><dc:creator>djmost</dc:creator><description>We are using v7.5 Build 31003. We are trying to understand who updated an extensionAttributes? How do I modify my Quick Search to look specifically for extensionAttrubtes?</description></item><item><title>Forum Post: EMC events on Syslog</title><link>https://www.quest.com/community/change-auditor/f/forum/37262/emc-events-on-syslog</link><pubDate>Mon, 30 Mar 2026 14:28:00 GMT</pubDate><guid isPermaLink="false">5f2f4fa7-ebc7-4803-900c-42d427844a5e:4565d514-a558-4947-a96e-e29d6dbd8c9b</guid><dc:creator>lffernandez</dc:creator><description>Hi, Can you include EMC events on syslog subscriptions? I don&amp;#39;t see them in the options to select.</description></item><item><title>Forum Post: RE: Reporting with Powershell</title><link>https://www.quest.com/community/change-auditor/f/forum/36525/reporting-with-powershell/86125</link><pubDate>Tue, 30 Dec 2025 07:54:00 GMT</pubDate><guid isPermaLink="false">5f2f4fa7-ebc7-4803-900c-42d427844a5e:cb839128-1614-42a0-a52b-df1034f8835b</guid><dc:creator>y r i xe lfie c o</dc:creator><description>Thank you for the information.</description></item><item><title>Forum Post: RE: Reporting with Powershell</title><link>https://www.quest.com/community/change-auditor/f/forum/36525/reporting-with-powershell/86106</link><pubDate>Tue, 23 Dec 2025 19:20:00 GMT</pubDate><guid isPermaLink="false">5f2f4fa7-ebc7-4803-900c-42d427844a5e:fb2ef062-2e50-4aa3-811d-6339af675c38</guid><dc:creator>djmost</dc:creator><description>I have looked at this section of the documentation. Unfortunately, it appears to build on an existing search with some filtering. We have tried unsuccessfully to build generic searches with specific filtering.</description></item><item><title>CA for SQL audit for read only Queries</title><link>https://www.quest.com/community/change-auditor/i/ideas/ca-for-sql-audit-for-read-only-queries</link><pubDate>Tue, 16 Sep 2025 08:24:00 GMT</pubDate><guid isPermaLink="false">5f2f4fa7-ebc7-4803-900c-42d427844a5e:ee40ef20-4cbf-4960-9513-29d40c98ad02</guid><dc:creator>rakesh chulliparambil</dc:creator><description>Since the Apex SQL is EOL, the customers are expecting CA to audit the read only queries performed on the SQL databases. At present CA does not audit anything read only performed against the SQL DBs The use case is for eg In Banking industry the PCI data is stored in SQL tables and any one who is trying to read this data should be audited though they do not perform any changes.</description></item><item><title>Protecting the CA Agent Services</title><link>https://www.quest.com/community/change-auditor/i/ideas/protecting-the-ca-agent-services</link><pubDate>Tue, 16 Sep 2025 07:53:00 GMT</pubDate><guid isPermaLink="false">5f2f4fa7-ebc7-4803-900c-42d427844a5e:66f2e360-827d-4633-8818-e5cd7c0d39cf</guid><dc:creator>rakesh chulliparambil</dc:creator><description>The CA Agents are running on Local system context in the domain controllers. This is a security RISK as this service can be exploited as the Local System on a DC is equivalent to Domain Administrator Privileges. Also the service can be stopped without any additional password. If the service is stopped the protection templates also stop working. We should ideally enable more security for this agent service to either remove it from local system context or enable a password to stop or disable the service like the Antivirus OEMS do.</description></item><item><title>Forum Post: Upgrade to 7.6</title><link>https://www.quest.com/community/change-auditor/f/forum/36678/upgrade-to-7-6</link><pubDate>Thu, 31 Jul 2025 16:09:00 GMT</pubDate><guid isPermaLink="false">5f2f4fa7-ebc7-4803-900c-42d427844a5e:bf86f06b-7652-4077-8d51-b7a61418f021</guid><dc:creator>lffernandez</dc:creator><description>Has anyone upgraded to 7.6? Any known issue? We are getting ready to upgrade and wanted to make sure. Thanks in advance.</description></item><item><title>Forum Post: RE: Reporting with Powershell</title><link>https://www.quest.com/community/change-auditor/f/forum/36525/reporting-with-powershell/85085</link><pubDate>Thu, 10 Jul 2025 15:22:00 GMT</pubDate><guid isPermaLink="false">5f2f4fa7-ebc7-4803-900c-42d427844a5e:581bc7ff-59e3-4eb8-9b44-660c134301a0</guid><dc:creator>JohnnyQuest</dc:creator><description>Have you looked at this part of the documentation? Take a look and feel free to post any follow-up questions.</description></item><item><title>Forum Post: Using Power BI</title><link>https://www.quest.com/community/change-auditor/f/forum/36526/using-power-bi</link><pubDate>Thu, 10 Jul 2025 13:19:00 GMT</pubDate><guid isPermaLink="false">5f2f4fa7-ebc7-4803-900c-42d427844a5e:5ef9aa0a-3a1f-4b4f-ac5a-488448e860ee</guid><dc:creator>djmost</dc:creator><description>We use quick searches to review specific events. Often, we would like to see the same type of quick search for multiple objects. Can we connect the underlying database to leverage Power BI to present the data?</description><category domain="https://www.quest.com/community/change-auditor/tags/Change%2bAuditor%2bfor%2bActive%2bDirectory">Change Auditor for Active Directory</category><category domain="https://www.quest.com/community/change-auditor/tags/Power%2bBI">Power BI</category></item><item><title>Forum Post: Reporting with Powershell</title><link>https://www.quest.com/community/change-auditor/f/forum/36525/reporting-with-powershell</link><pubDate>Thu, 10 Jul 2025 13:16:00 GMT</pubDate><guid isPermaLink="false">5f2f4fa7-ebc7-4803-900c-42d427844a5e:50b78714-0d66-42ac-90fd-9ad2434697d0</guid><dc:creator>djmost</dc:creator><description>We use quick searches to review specific events. Often, we would like to see the same type of quick search for multiple objects. Has anyone been able to leverage Powershell to query instead of performing a Quick Search?</description><category domain="https://www.quest.com/community/change-auditor/tags/Change%2bAuditor%2bfor%2bActive%2bDirectory">Change Auditor for Active Directory</category><category domain="https://www.quest.com/community/change-auditor/tags/Powershell">Powershell</category></item><item><title>Forum Post: RE: Custom Search Filter for Users</title><link>https://www.quest.com/community/change-auditor/f/forum/36394/custom-search-filter-for-users/84684</link><pubDate>Fri, 30 May 2025 21:03:00 GMT</pubDate><guid isPermaLink="false">5f2f4fa7-ebc7-4803-900c-42d427844a5e:65fdf7a8-c14e-4a9f-bf24-93144e3e2b1b</guid><dc:creator>jim.cochran</dc:creator><description>Doh! That&amp;#39;s an excellent idea. I don&amp;#39;t currently have them in that group, but would be really easy to do and enforce with ARS. Thank you!!!</description></item><item><title>Forum Post: RE: Custom Search Filter for Users</title><link>https://www.quest.com/community/change-auditor/f/forum/36394/custom-search-filter-for-users/84682</link><pubDate>Fri, 30 May 2025 17:25:00 GMT</pubDate><guid isPermaLink="false">5f2f4fa7-ebc7-4803-900c-42d427844a5e:5de0c398-9d23-4dc9-8fc5-906a1b92cede</guid><dc:creator>JohnnyQuest</dc:creator><description>Another idea popped into my head - do you have an AD group that contains all people identified as employees via EA11? If you do then you could use the fact that the user being disabled is a member of that group to scope them into the search results.</description></item><item><title>Forum Post: RE: Custom Search Filter for Users</title><link>https://www.quest.com/community/change-auditor/f/forum/36394/custom-search-filter-for-users/84681</link><pubDate>Fri, 30 May 2025 17:23:00 GMT</pubDate><guid isPermaLink="false">5f2f4fa7-ebc7-4803-900c-42d427844a5e:9f5e73f4-12ba-4f71-b2fe-311101cd87af</guid><dc:creator>JohnnyQuest</dc:creator><description>My pleasure. The challenge is that within the Change Auditor UI, there is no way to build a filter on that attribute because it&amp;#39;s not being stored for every user and thus not available in the Who/What/Where tabs nor on the &amp;quot;Layout&amp;quot; tab for the Search. Now, what you could do is modify the actual SQL code for the Search (exposed on the SQL tab) and shoehorn in some code in there that would fetch the attribute from AD on the fly and check for your value. This would slow down the execution of the search. You would have to test to see whether it&amp;#39;s worth the performance hit.</description></item><item><title>Forum Post: RE: Custom Search Filter for Users</title><link>https://www.quest.com/community/change-auditor/f/forum/36394/custom-search-filter-for-users/84680</link><pubDate>Fri, 30 May 2025 15:37:00 GMT</pubDate><guid isPermaLink="false">5f2f4fa7-ebc7-4803-900c-42d427844a5e:b876d172-f5b4-4c86-822c-c7fb99083f5b</guid><dc:creator>jim.cochran</dc:creator><description>Thank you, I appreciate you taking the time to respond. I can manage the query in Powershell, but I was looking to create a smart alert from CA that would notify me anytime a user with that attribute set to that value was disabled.</description></item><item><title>Forum Post: RE: Custom Search Filter for Users</title><link>https://www.quest.com/community/change-auditor/f/forum/36394/custom-search-filter-for-users/84679</link><pubDate>Fri, 30 May 2025 14:37:00 GMT</pubDate><guid isPermaLink="false">5f2f4fa7-ebc7-4803-900c-42d427844a5e:8d237730-1d16-4cb0-b984-48268177d3ee</guid><dc:creator>JohnnyQuest</dc:creator><description>Just to be clear on what you need: You want a search for all transactions where a user account was disabled and the extensionattribute11 of that user equals the string &amp;quot;employee&amp;quot;. The challenge is that Change Auditor doesn&amp;#39;t store the contents of extensionattribute11 for any user except for the case where a transaction involves the attribute being modified. So you would probably have to compile your &amp;quot;report&amp;quot; in two steps: 1) Generate a Search for all account disable transactions 2) Take the list of usernames that you get from that and check each one&amp;#39;s extensionattribute11 (EA11) in Active Directory. I would approach this task with a Powershell script that would combine extracting the Change Auditor data and then performing the EA11 lookup. Information on performing searches with Powershell may be found here For querying AD, you would just use the native Active Directory cmdlets. So probably Get-ADUser. If you come up with some code and it doesn&amp;#39;t quite get you what you need, feel free to post it here and someone like me will give you a hand.</description></item><item><title>Forum Post: Custom Search Filter for Users</title><link>https://www.quest.com/community/change-auditor/f/forum/36394/custom-search-filter-for-users</link><pubDate>Thu, 29 May 2025 20:22:00 GMT</pubDate><guid isPermaLink="false">5f2f4fa7-ebc7-4803-900c-42d427844a5e:a2bd8680-1ab0-458b-8a8f-302ba5a11061</guid><dc:creator>jim.cochran</dc:creator><description>I want to search for all disabled users where &amp;quot;extensionAttribute11&amp;quot; = &amp;quot;employee&amp;quot; Is this possible?</description></item><item><title>Forum Post: RE: Failed Group Policy Container Access (Change Auditor Protection)</title><link>https://www.quest.com/community/change-auditor/f/forum/32384/failed-group-policy-container-access-change-auditor-protection/84552</link><pubDate>Tue, 20 May 2025 14:45:00 GMT</pubDate><guid isPermaLink="false">5f2f4fa7-ebc7-4803-900c-42d427844a5e:0bceb224-1119-4cbd-a066-fa9b9e90e06c</guid><dc:creator>joe.white</dc:creator><description>Encountered the similar issue. Here is a synopsis of what was done, seen, and steps take to resolve USERA: Authorized Domain Admin, whom was configured in CA-Protection as an Override Account (by AD group membership) Logged into Domain Controller (DC1) GPMC was opened on DC1, but connected to DC-2 (assume the Domain Admn had configured GPMC to connect DC2 sometime in the past) The Default Domain Policy was modified by USERA Change Auditor shows Events of Group Policy change was successful by USERA Started getting repeated alerts that Protected GP was triggering &amp;quot;“Access to Group Policy Default Domain Policy was denied” for User (DC2) Had USERA change the GPMC connection to DC1, and not DC2 Protected Events continued repeating every 3-6 minutes Added DC-2 to as an “Override account” in CA-Protection, Protected Events continued repeating every 3-6 minutes Restarted DC-2 The Protected Events Stopped Note, the Group Policy itself was consistent with the change made throughout all Domain Controllers in the Enterprise (DFS-R of the SYSVOL) The GP on DC-2 (Sysvol) was confirmed to have the changes, even while the Protection events were occurring Unsure why Domain Controllers are not by Default consider Override Accounts for all AD objects And unsure what DC-2 was trying to do exactly The going theory is that GPMC somehow kept the GP Container open in a State Protection could not access. How\Why , unknown</description></item><item><title>Forum Post: Cleanup-Activity from Change Auditor for Active Directory for Decommissioned DC's</title><link>https://www.quest.com/community/change-auditor/f/forum/36237/cleanup-activity-from-change-auditor-for-active-directory-for-decommissioned-dc-s</link><pubDate>Tue, 22 Apr 2025 06:26:00 GMT</pubDate><guid isPermaLink="false">5f2f4fa7-ebc7-4803-900c-42d427844a5e:4f299c35-1207-49b6-b726-ec4c3135343c</guid><dc:creator>prabhbhangu1998</dc:creator><description>Hi Experts, What cleanup activities can be performed on decommissioned DCs as well in CAAD portal in perspective of Change Auditor for Active Directory?</description><category domain="https://www.quest.com/community/change-auditor/tags/Change%2bAuditor%2bfor%2bActive%2bDirectory">Change Auditor for Active Directory</category></item><item><title>Forum Post: Licensing</title><link>https://www.quest.com/community/change-auditor/f/forum/36120/licensing</link><pubDate>Thu, 27 Mar 2025 13:24:00 GMT</pubDate><guid isPermaLink="false">5f2f4fa7-ebc7-4803-900c-42d427844a5e:b266c9a5-c93b-4268-8699-12e2d61d3356</guid><dc:creator>renato cardia</dc:creator><description>Do users who are listed as guests in Azure, for instance, to access the VPN or share data via SharePoint, also need to be licensed? Or is the licensing requirement applicable only to employees? Thank you</description></item><item><title>Forum Post: Schedule Report - List group membership</title><link>https://www.quest.com/community/change-auditor/f/forum/36076/schedule-report---list-group-membership</link><pubDate>Fri, 21 Mar 2025 14:06:00 GMT</pubDate><guid isPermaLink="false">5f2f4fa7-ebc7-4803-900c-42d427844a5e:144f6e31-738d-477a-8afc-13bc4acae8d3</guid><dc:creator>tomas montiel</dc:creator><description>I would like to create a weekly report that lists the current members of a specific group. Although I have set up alerts for changes within the group, I also want to receive a weekly report detailing the current members. Can I make this report in Change Auditor?</description></item></channel></rss>