If you've got the necessary auditing enabled in
your domain, and you had auditing ACEs configured on the DNS zone (location
depends, generally you'd set it on CN=MicrosoftDNS folder) then yes, you
can. But you'll have to search each DCs security event log for this
info.
Otherwise, you can't get this info. You can
check the whenChanged attribute on the tombstoned record for a rough
idea of when the deletion occurred and try and move from there by looking at
logon events, again if you have auditing enabled.
If you're not using AD-Integrated DNS, then none
of the above will really help.
--Paul
|
- [ActiveDir] OT: DNS entry James Carter
- Re: [ActiveDir] OT: DNS entry Paul Williams
- RE: [ActiveDir] OT: DNS entry neil.ruston
- RE: [ActiveDir] OT: DNS entry neil.ruston
- RE: [ActiveDir] OT: DNS entry James Carter
- RE: [ActiveDir] OT: DNS entry neil.ruston
- RE: [ActiveDir] OT: DNS entry James Carter
- RE: [ActiveDir] OT: DNS entry Marcus.Oh
- RE: [ActiveDir] OT: DNS entry ai-chung_chong
- RE: [ActiveDir] OT: DNS entry neil.ruston
- RE: [ActiveDir] OT: DNS entry neil.ruston