Hello There...
I have a globle group name "My Enterprise Admin" who is a member of
Domain Admin in AD.
I created another group name "Admin Manger Enterprise".
I added Admin Manage Entrprise in a security tab of "My Enterprise
Admin" Group and assigb Add/Remove self as a member permission.
After an hour this group is removed from the permission.
And I found following in event log:
Event Type: Success Audit
Event Source: Security
Event Category: Account Management
Event ID: 641
Date: 6/16/2008
Time: 1:26:35 PM
User: NT AUTHORITY\ANONYMOUS LOGON
Computer: DC0001$
Description:
Security Enabled Global Group Changed:
Target Account Name: Admin Manger Enterprise
Target Domain: POWER
Target Account ID: POWER\Domain Admins
Caller User Name: DC0001$
Caller Domain: POWER
Caller Logon ID: (0x0,0x3E7)
Privileges: -
Changed Attributes:
Sam Account Name: -
Sid History: -
For more information, see Help and Sup****t Center at
http://go.microsoft.com/fwlink/events.asp.