Audience
IT security teams, Active Directory administrators, Microsoft 365 administrators, SOC teams, compliance professionals, security auditors, and enterprises that need real-time auditing, threat monitoring, forensic investigation, and change tracking across hybrid Microsoft infrastructure
About Quest Change Auditor
Quest Change Auditor is a security monitoring and IT auditing platform for tracking user, administrator, configuration, and authentication activity across hybrid Microsoft environments. It provides real-time auditing and threat monitoring across Active Directory, Azure AD, Office 365, Windows Server, Exchange, SQL Server, network-attached storage, SharePoint, and OneDrive for Business. The platform detects indicators of compromise, suspicious user activity, lateral movement, and authentication-related threats that may indicate ransomware or other attacks. Change Auditor can block unauthorized changes to critical groups, Group Policy settings, sensitive mailboxes, and the Active Directory database, even when attackers have obtained privileged credentials. Its auditing engine translates system activity into normalized records showing who made a change, what changed, when and where it occurred, the originating workstation, and before-and-after values.