I have another department logging onto a server without authorization. I want to determine if they added a feature without following the proper procedure.
Asked
Active
Viewed 2.3k times
1 Answers
9
You can use Event Viewer for this. Open Event Viewer, then expand Windows Logs, and click on Setup.
You'll want to create a filter that looks for these keywords: Microsoft-Windows-ServerManager or just ServerManager or Event IDs 1611 & 1610. Preferably filtering for the event IDs.
For Roles, look for event ID 1611
For Features, look for event ID 1610
Example of Features added screenshot in the Event Viewer on my lab server:

Brad Bouchard
- 2,537
-
Is this valid for features too? – MVCylon May 07 '14 at 18:48
-
Yes, see my answer edits. Look for Event ID 1610 (Features) instead of 1611 (Roles) – Brad Bouchard May 07 '14 at 19:02
-
Were you able to try it yet @MVCylon ? – Brad Bouchard May 07 '14 at 20:34
-
Worked like a charm! – MVCylon May 09 '14 at 14:25
-
Glad to hear it. – Brad Bouchard May 09 '14 at 14:42