Changes to the directory objects for Foreign Security Principals are being reported as made by system

Email It to Me Print this Page
The ForeignSecurityPrincipals container in Active Directory represent security principals from trusted domains external to the forest, and allows foreign security principals to become members of groups within the domain. The ForeignSecurityPrincipals  objects are being created automatically by system (Active Directory), so having changes of the foreignSecurityPrincipal object reported as made by system is a normal behavior of the Netwrix Auditor.
 
AddedforeignSecurityPrincipal4/12/2013 09:41:21systemunknown\local\domainx\ForeignSecurityPrincipals\S-1-5-20-684578120-14483156-1569713544-17821none
AddedforeignSecurityPrincipal4/12/2013 09:41:21systemunknown\local\domainx\ForeignSecurityPrincipals\S-1-5-20-684578120-14483156-1569713544-17821none
AddedforeignSecurityPrincipal4/12/2013 09:41:21systemunknown\local\domainx\ForeignSecurityPrincipals\S-1-5-20-684578120-14483156-1569713544-11394none
AddedforeignSecurityPrincipal4/12/2013 09:41:21systemunknown\local\domainx\ForeignSecurityPrincipals\S-1-5-20-684578120-14483156-1569713544-4736none
  
For more information regarding the ForeignSecurityPrincipals container and the ForeignSecurityPrincipals objects please refer to the following Microsoft KB articles: 

http://technet.microsoft.com/en-us/library/cc779144(v=WS.10).aspx
http://technet.microsoft.com/en-us/library/cc755427(v=WS.10).aspx
 
Was this information helpful?