Feature request: Alert when user or group added or removed from local Administrators group
B
Ben Cundiff
We're concerned about a scenario where an attacker gains foothold and then creates local accounts or adds a compromised account to local Administrators group or similar. We're also concerned about scenarios where client admins make local accounts for whatever reason (troubleshooting GPOs, software, etc) and then forget to disable them, etc.
Y
Yossi Leitner
With an option of username exclusions, to exclude IT's admin users