TransWikia.com

Extended event to track the logins from a specific login, but that login is filtering on a an active directory group

Database Administrators Asked by datadawg2000 on December 15, 2021

I’m wondering if there is a way to do this in sql server. I have an extended event set up to track all user logins from a database with a filter. The way our security is setup, we have active directly groups that we give the access to, and when users login, they are authenticated with their individual active directory account based on belong to the AD group that is granted database permissions.

However, the extended event information only shows that specific user, not the AD group they are authenticating to. For example, if I want to only track logins from DBAs, we have an AD group CompanyDBA, and when I login as a member, I authenticate with my CompanyUser_ID account. However, in the extended event, I only see filters for the specific user, it doesn’t display the CompanyDBA AD group I’m authenticating with or give me the option to filter from it. Anyone know how to show and filter off of that AD group instead?

One Answer

You cannot filter on the AD group. This previous question explains how the access management works with AD groups:
How to tell which windows group login I used when logging in via windows authentication

Answered by Dominique Boucher on December 15, 2021

Add your own answers!

Ask a Question

Get help from others!

© 2024 TransWikia.com. All rights reserved. Sites we Love: PCI Database, UKBizDB, Menu Kuliner, Sharing RPP