Can someone lead me in the right direction on how to find out what service/user is running a script by development that deletes users/computers from Active Directory based on certain criteria. is there a way to lead the user/service to the script? I set auditing on Object Access and it shows Events logged on this item to be audited. I set it in ADSI on the whole schema. The Events say a number but can someone tell me how to decipher these object accesses? I tested with my user account and it does show up when I move object in different OU's but there is a script running somewhere that is actually deleting and I know because I see the tombstones but do not know who is doing this. Thank you,