How To Detect Who Disabled A User Account In Active Directory

The method below works well for Windows Server 2008 and later. If a user has been deleted from the Active Directory, they won't be able to log into the systems using Windows Authentication. Setting up security logs with a history can help you identify who disabled a user account. 1) Configure Audit Settings Run gpedit.msc [...]