Monitor privileged account usage

Prev Next

You can ensure that administrative and service accounts are used appropriately and to detect any unauthorized or risky activity.

  1. Use the Privilege level search filter to narrow your search to specific administrative groups:

    • Domain Admin: Shows logons by members of highly privileged Active Directory groups.

    • Local Admin: Shows logons by members of the local administrators group on an endpoint.

  2. Alternatively, use the Domain group membership search to look for activity from custom administrative groups specific to your organization (for example, Tier 1 Support).

  3. Review the activity for these accounts. Look for logons to standard user workstations or systems that the administrator has no business accessing.