{"id":72392,"date":"2015-07-03T00:01:00","date_gmt":"2015-07-03T00:01:00","guid":{"rendered":"https:\/\/blogs.technet.microsoft.com\/heyscriptingguy\/2015\/07\/03\/use-powershell-to-find-changes-to-active-directory\/"},"modified":"2019-02-18T09:47:13","modified_gmt":"2019-02-18T16:47:13","slug":"use-powershell-to-find-changes-to-active-directory","status":"publish","type":"post","link":"https:\/\/devblogs.microsoft.com\/scripting\/use-powershell-to-find-changes-to-active-directory\/","title":{"rendered":"Use PowerShell to Find Changes to Active Directory"},"content":{"rendered":"<p><b style=\"font-size:12px\">Summary<\/b><span style=\"font-size:12px\">: Microsoft Scripting Guy, Ed Wilson, talks about using Windows PowerShell to find changes to Active Directory.<\/span>\n<img decoding=\"async\" src=\"https:\/\/devblogs.microsoft.com\/wp-content\/uploads\/sites\/29\/2019\/02\/q-for-powertip.jpg\" alt=\"Hey, Scripting Guy! Question\">&nbsp;Hey, Scripting Guy! I have this problem. It seems our company has undergone a lot of changes recently, and I need to find what changes have impacted Active Directory. Basically, I do not even know where to start. I would like to get an overview of what things have changed since a specific date. Is this even possible with Windows PowerShell?\n&mdash;GF\n<img decoding=\"async\" src=\"https:\/\/devblogs.microsoft.com\/wp-content\/uploads\/sites\/29\/2019\/02\/a-for-powertip.jpg\" alt=\"Hey, Scripting Guy! Answer\">&nbsp;Hello GF,\nMicrosoft Scripting Guy, Ed Wilson, is here. Hey, the weekend is nearly here&mdash;at least if you live on the eastern coast of the United States. If you are in Australia, then the weekend is already underway. That is one thing I love about Australia, they always start the weekend early. Anyway, it should be a nice sunny weekend around here, and there are outdoor concerts planned. It should be a great time to get out and have some fun.\nSo GF, I will help you out so maybe you can get out of the office and enjoy some nice sunny outdoor weather.\nTwo things are required to find when things changed. The first thing you need to find when things changed is a date. This becomes your point of departure. If you were looking for a ship, it would be your datum. As it is, you don&rsquo;t really know what you are looking for, so you need to create a <b>DateTime<\/b> object.\nThe easiest way to do this is to use the <b>[datetime]<\/b> type accelerator to convert a string into a <b>DateTime<\/b> object for you. I can supply the date in a format that my local input will accept, so for me that becomes month, day, year.\nHere is the command I use to create a <b>DateTime<\/b> object that I will use as my beginning point of search. (By the way, I am not going to give a time, so the time will begin at midnight.)<\/p>\n<p style=\"margin-left:30px\">$dte = [datetime]&#8221;1\/1\/2015&#8243;\nAs you can see here, I have created a <b>DateTime<\/b> object for January 1, 2015 (which was a Thursday):<\/p>\n<p style=\"margin-left:30px\">PS C:\\&gt; $dte<\/p>\n<p style=\"margin-left:30px\">Thursday, January 1, 2015 12:00:00 AM\nNow I need to find all objects in Active Directory that have a <b>WhenChanged<\/b> property (attribute) that is greater than January 1, 2015 at midnight. Because GF only says he is interested in knowing the numbers of the different types of objects that changed, I pipe the output to the <b>Group-Object<\/b> cmdlet.\nTo be able to know what types of objects are changed, I will need the <b>ObjectClass<\/b> property. To find objects in Active Directory, I use the <b>Get-ADObject<\/b> cmdlet. My filter uses the <b>WhenChanged<\/b> property and I specify my <b>DateTime<\/b> object that I stored in the <b>$dte<\/b> variable. Here is the command I use:<\/p>\n<p style=\"margin-left:30px\">Get-ADObject -Filter &#8216;whenchanged -gt $dte&#8217; | Group-Object objectclass\nAnd here is an example of the type of output that arrives:<\/p>\n<p style=\"margin-left:30px\">PS C:\\&gt; Get-ADObject -Filter &#8216;whenchanged -gt $dte&#8217; | Group-Object objectclass<\/p>\n<p style=\"margin-left:30px\">Count Name&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; Group&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;<\/p>\n<p style=\"margin-left:30px\">&#8212;&#8211; &nbsp; &nbsp; &#8212;- &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp;&#8212;&#8211;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; &nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;<\/p>\n<p style=\"margin-left:30px\">&nbsp;&nbsp;&nbsp; 1 domainDNS&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; {DC=NWTraders,DC=com}&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;<\/p>\n<p style=\"margin-left:30px\">&nbsp;&nbsp;&nbsp; 1 groupPolicyContainer&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; {CN={31B2F340-016D-11D2-945F-00C04FB984F9},CN=Policies,&#8230;<\/p>\n<p style=\"margin-left:30px\">&nbsp; &nbsp; 1257 user&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; {CN=Administrator,CN=Users,DC=NWTraders,DC=com, CN=Kim &#8230;<\/p>\n<p style=\"margin-left:30px\">&nbsp;&nbsp;&nbsp; 1 group&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; {CN=Remote Desktop Users,CN=Builtin,DC=NWTraders,DC=com}&nbsp;<\/p>\n<p style=\"margin-left:30px\">&nbsp;&nbsp;&nbsp; 6 computer&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; {CN=DC1,OU=Domain Controllers,DC=NWTraders,DC=com, CN=S&#8230;<\/p>\n<p style=\"margin-left:30px\">&nbsp;&nbsp;&nbsp; 1 rIDManager&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; &nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;{CN=RID Manager$,CN=System,DC=NWTraders,DC=com}&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;<\/p>\n<p style=\"margin-left:30px\">&nbsp;&nbsp;&nbsp; 1 rIDSet&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; {CN=RID Set,CN=DC1,OU=Domain Controllers,DC=NWTraders,D&#8230;<\/p>\n<p style=\"margin-left:30px\">&nbsp;&nbsp;&nbsp; 2 serviceConnectionPoint&nbsp;&nbsp;&nbsp; {CN=Windows Virtual Machine,CN=SGW,CN=Computers,DC=NWTr&#8230;<\/p>\n<p style=\"margin-left:30px\">&nbsp;&nbsp;&nbsp; 1 rRASAdministrationConn&#8230; {CN=RouterIdentity,CN=SGW,CN=Computers,DC=NWTraders,DC=&#8230;<\/p>\n<p style=\"margin-left:30px\">&nbsp;&nbsp;&nbsp; 2 organizationalUnit&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; {OU=dataImport,DC=NWTraders,DC=com, OU=Charlotte,DC=NWT&#8230;\nWhat does this output tell me? Well, it tells me that something changed in DNS, Group Policy, groups, computers, organizational units, and on and on. What I do not know is what changed.\nWas an organizational unit (or two) created or merely modified? The 1257 users could be new users or changed users. When a user changes the password (which hopefully would have happened a few times since January 1, 2015), the user object changes. The same thing for the six computer objects&mdash;they have passwords that automatically change.\nIf you are looking for when things were created, well, guess what? There is also a <b>WhenCreated<\/b> property (attribute). I can modify my code a little bit to see what objects were created after a specific date. This time, I will change my date to show objects that were created since July 1, 2015. The output is shown here:<\/p>\n<p style=\"margin-left:30px\">PS C:\\&gt; $dte = [datetime]&#8221;7\/1\/15&#8243;<\/p>\n<p style=\"margin-left:30px\"><span style=\"font-size:12px\">PS C:\\&gt; $dte<\/span><\/p>\n<p style=\"margin-left:30px\">&nbsp;<span style=\"font-size:12px\">Wednesday, July 1, 2015 12:00:00 AM<\/span><\/p>\n<p style=\"margin-left:30px\"><span style=\"font-size:12px\">PS C:\\&gt; Get-ADObject -Filter &#8216;whencreated -gt $dte&#8217; | Group-Object objectclass<\/span><\/p>\n<p style=\"margin-left:30px\">Count Name&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; Group&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;<\/p>\n<p style=\"margin-left:30px\">&#8212;&#8211; &nbsp; &nbsp; &#8212;- &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp;&#8212;&#8211; &nbsp;&nbsp;<span style=\"font-size:12px\">&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp;&nbsp;<\/span><\/p>\n<p style=\"margin-left:30px\">&nbsp;&nbsp;&nbsp; 1 organizationalUnit&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; {OU=Charlotte,DC=NWTraders,DC=com}&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;\nSo, only one object has been created in Active Directory since July 1, 2015. And because there is only one object, it shows up in the <b>Group<\/b> property from <b>Group-Object<\/b>. It is the Charlotte organizational unit. If there were more than one object, I might not be able to see the group details. So I would remove the <b>Group-Object<\/b> command. Here is the output:<\/p>\n<p style=\"margin-left:30px\">PS C:\\&gt; Get-ADObject -Filter &#8216;whencreated -gt $dte&#8217;<\/p>\n<p style=\"margin-left:30px\"><span style=\"font-size:12px\">DistinguishedName&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; Name&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; ObjectClass&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; ObjectGUID &nbsp; &nbsp; &nbsp; &nbsp; &nbsp;<\/span><\/p>\n<p style=\"margin-left:30px\">&#8212;&#8212;&#8212;&#8212;&#8212;&#8211; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp;&#8212;- &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp;&#8212;&#8212;&#8212;&#8211; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp;&#8212;&#8212;&#8212;-&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;<\/p>\n<p style=\"margin-left:30px\">OU=Charlotte,DC=NWT&#8230; Charlotte&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; organizationalUnit&nbsp;&nbsp;&nbsp;&nbsp; f53f519c-c548-401a&#8230;\n<span style=\"font-size:12px\">If I want to see all of the properties (attributes) from the newly created object, I specify the <\/span><b style=\"font-size:12px\">&ndash;properties<\/b><span style=\"font-size:12px\"> parameter and use the asterisk wildcard character ( <\/span><b style=\"font-size:12px\">*<\/b><span style=\"font-size:12px\"> ) to select all of the properties. This command is shown here with the associated output from the command:<\/span><\/p>\n<p style=\"margin-left:30px\">PS C:\\&gt; Get-ADObject -Filter &#8216;whencreated -gt $dte&#8217; -Properties *<\/p>\n<p style=\"margin-left:30px\"><span style=\"font-size:12px\">CanonicalName&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; : NWTraders.com\/Charlotte<\/span><\/p>\n<p style=\"margin-left:30px\">CN&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; :<\/p>\n<p style=\"margin-left:30px\">Created&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; : 7\/2\/2015 9:47:53 AM<\/p>\n<p style=\"margin-left:30px\">createTimeStamp&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; : 7\/2\/2015 9:47:53 AM<\/p>\n<p style=\"margin-left:30px\">Deleted&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; :<\/p>\n<p style=\"margin-left:30px\">Description&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; &nbsp;: Charlotte office users<\/p>\n<p style=\"margin-left:30px\">DisplayName&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; :<\/p>\n<p style=\"margin-left:30px\">DistinguishedName&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; : OU=Charlotte,DC=NWTraders,DC=com<\/p>\n<p style=\"margin-left:30px\">dSCorePropagationData&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; : {12\/31\/1600 7:00:00 PM}<\/p>\n<p style=\"margin-left:30px\">instanceType&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; : 4<\/p>\n<p style=\"margin-left:30px\">isDeleted&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; :<\/p>\n<p style=\"margin-left:30px\">LastKnownParent&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; :<\/p>\n<p style=\"margin-left:30px\">Modified&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; : 7\/2\/2015 9:47:53 AM<\/p>\n<p style=\"margin-left:30px\">modifyTimeStamp&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; : 7\/2\/2015 9:47:53 AM<\/p>\n<p style=\"margin-left:30px\">Name&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; : Charlotte<\/p>\n<p style=\"margin-left:30px\">nTSecurityDescriptor&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; : System.DirectoryServices.ActiveDirectorySecurity<\/p>\n<p style=\"margin-left:30px\">ObjectCategory&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; : CN=Organizational-Unit,CN=Schema,CN=Configuration,DC=NWT<\/p>\n<p style=\"margin-left:30px\">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; raders,DC=com<\/p>\n<p style=\"margin-left:30px\">ObjectClass&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; : organizationalUnit<\/p>\n<p style=\"margin-left:30px\">ObjectGUID&nbsp;&nbsp;&nbsp;&nbsp; &nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;: f53f519c-c548-401a-982d-bd9f38b20d97<\/p>\n<p style=\"margin-left:30px\">ou&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; : {Charlotte}<\/p>\n<p style=\"margin-left:30px\">ProtectedFromAccidentalDeletion : False<\/p>\n<p style=\"margin-left:30px\">sDRightsEffective&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; : 15<\/p>\n<p style=\"margin-left:30px\">uSNChanged&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; : 430200<\/p>\n<p style=\"margin-left:30px\">uSNCreated&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; : 430200<\/p>\n<p style=\"margin-left:30px\">whenChanged&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; : 7\/2\/2015 9:47:53 AM<\/p>\n<p style=\"margin-left:30px\">whenCreated&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; : 7\/2\/2015 9:47:53 AM\n<span style=\"font-size:12px\">What does not appear here is who created the object. To find this information, I would need to enable auditing for the creation of Active Directory objects. For me, that is pretty much a one-off scenario, so I would use the GUI tools to do that, and I would not use Windows PowerShell to turn on auditing.<\/span>\nGF, that is all there is to using Windows PowerShell to find changes to Active Directory. This also concludes Active Directory Week. Join me tomorrow when I will have a way cool guest blog post.\nI invite you to follow me on <a href=\"http:\/\/bit.ly\/scriptingguystwitter\" target=\"_blank\">Twitter<\/a> and <a href=\"http:\/\/bit.ly\/scriptingguysfacebook\" target=\"_blank\">Facebook<\/a>. If you have any questions, send email to me at <a href=\"http:\/\/blogs.technet.commailto:scripter@microsoft.com\" target=\"_blank\">scripter@microsoft.com<\/a>, or post your questions on the <a href=\"http:\/\/bit.ly\/scriptingforum\" target=\"_blank\">Official Scripting Guys Forum<\/a>. See you tomorrow. Until then, peace.\n<b>Ed Wilson, Microsoft Scripting Guy<\/b><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Summary: Microsoft Scripting Guy, Ed Wilson, talks about using Windows PowerShell to find changes to Active Directory. &nbsp;Hey, Scripting Guy! I have this problem. It seems our company has undergone a lot of changes recently, and I need to find what changes have impacted Active Directory. Basically, I do not even know where to start. [&hellip;]<\/p>\n","protected":false},"author":596,"featured_media":87096,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"footnotes":""},"categories":[1],"tags":[7,3,303,45],"class_list":["post-72392","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-scripting","tag-active-directory","tag-scripting-guy","tag-searching","tag-windows-powershell"],"acf":[],"blog_post_summary":"<p>Summary: Microsoft Scripting Guy, Ed Wilson, talks about using Windows PowerShell to find changes to Active Directory. &nbsp;Hey, Scripting Guy! I have this problem. It seems our company has undergone a lot of changes recently, and I need to find what changes have impacted Active Directory. Basically, I do not even know where to start. [&hellip;]<\/p>\n","_links":{"self":[{"href":"https:\/\/devblogs.microsoft.com\/scripting\/wp-json\/wp\/v2\/posts\/72392","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/devblogs.microsoft.com\/scripting\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/devblogs.microsoft.com\/scripting\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/devblogs.microsoft.com\/scripting\/wp-json\/wp\/v2\/users\/596"}],"replies":[{"embeddable":true,"href":"https:\/\/devblogs.microsoft.com\/scripting\/wp-json\/wp\/v2\/comments?post=72392"}],"version-history":[{"count":0,"href":"https:\/\/devblogs.microsoft.com\/scripting\/wp-json\/wp\/v2\/posts\/72392\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/devblogs.microsoft.com\/scripting\/wp-json\/wp\/v2\/media\/87096"}],"wp:attachment":[{"href":"https:\/\/devblogs.microsoft.com\/scripting\/wp-json\/wp\/v2\/media?parent=72392"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/devblogs.microsoft.com\/scripting\/wp-json\/wp\/v2\/categories?post=72392"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/devblogs.microsoft.com\/scripting\/wp-json\/wp\/v2\/tags?post=72392"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}