---
title: "How to Track Active Directory Changes with WMI Events"
description: "Learn how to track Active Directory changes to users in this informative tutorial on using WMI events."
canonical: "https://adamtheautomator.com/track-active-directory-changes/"
---

# How to Track Active Directory Changes with WMI Events

> Learn how to track Active Directory changes to users in this informative tutorial on using WMI events.

Source: https://adamtheautomator.com/track-active-directory-changes/

---

ATA Learning

Tap to hide

[

ATA Learning

](/)

*   [Home](/)
*   [Tutorials](/tutorials/)
*   [Instructors](/author/)
*   [Advertising](/advertising/)
*   [Recommended Resources](/resources/)
*   [About Adam](/about-adam/)

Search for:  

*   [](https://twitter.com/adbertram)
*   [](https://github.com/Adam-the-Automator)
*   [](https://www.linkedin.com/company/adam-the-automator-llc)
*   [](/feed/)

![How to Track Active Directory Changes with WMI Events](https://adamtheautomator.com/wp-content/uploads/2021/05/How-to-Track-Active-Directory-Changes-with-WMI-Events.jpg)

# How to Track Active Directory Changes with WMI Events

[![](https://secure.gravatar.com/avatar/5cd71a4e2894e3d2608b9e07347e05b85fa86e0955eb3f708412e6b9da7fd920?s=192&d=mm&r=g)Faris Malaeb](https://adamtheautomator.com/author/faris/)5 May 20214 min. read

Categories: [IT Ops](/category/it-ops/)

Tags:[Active Directory](/tag/active-directory/)

Table of Contents

*   [Prerequisites](#h-prerequisites)
*   [Finding Active Directory Groups with WMI](#h-finding-active-directory-groups-with-wmi)
*   [Creating a WMI Event Subscription](#h-creating-a-wmi-event-subscription)
*   [Develop the WQL Query](#h-develop-the-wql-query)
*   [Create the WMI Subscription in PowerShell](#h-create-the-wmi-subscription-in-powershell)
*   [Reading WMI Events](#h-reading-wmi-events)
*   [Conclusion](#h-conclusion)

Active Directory is a critical component of many organizations. It can also get overwhelming containing hundreds of thousands of objects changing constantly. Luckily, you can track Active Directory changes with some PowerShell expertise and a little time.

In this tutorial, you’re going to learn how to use WMI events to track Active Directory changes and keep you in the know about what’s going on with your Active Directory objects!

Related:[Using WMI in PowerShell](https://adamtheautomator.com/powershell-wmi/)

## Prerequisites

This article will be a hands-on tutorial. If you’d like to follow along, be sure you have the following:

*   An [Active Directory domain](https://docs.microsoft.com/en-us/windows-server/identity/ad-ds/deploy/install-active-directory-domain-services--level-100-) – This tutorial will use Windows Server 2019 with an Active Directory and forest functional level set to 2019, but domain controllers (DCs) running Windows 2008 R2 or later should work. The tutorial will be using a domain called _test.local_ with two DCs, DC01 and DC02.

Related:[Domain Controllers vs Active Directory](https://adamtheautomator.com/domain-controller-vs-active-directory/)

*   A domain-joined Windows PC with PowerShell installed. This tutorial will use Windows 10 with Windows PowerShell v5.1 or PowerShell 7.
*   PowerShell Active Directory Module.
*   A user account as a member of the Domain Admins groups in the domain.

## Finding Active Directory Groups with WMI

Before you can get notified when an object changes in Active Directory, you must first know the [WMI class](https://docs.microsoft.com/en-us/windows/win32/wmisdk/wmi-classes) that the WMI event will show up in and query group members. To do that, on a DC:

1\. Open PowerShell.

2\. Run `Get-CimClass` to connect to the namespace and find all available classes in the namespace. In the `CimClassName` column, you’ll see a `ds_group`. This class lists all groups in Active Directory and their attributes.

```powershell
Get-CimClass -Namespace 'ROOT\Directory\LDAP'
```

![ds\_group Active Directory WMI attribute](https://adamtheautomator.com/wp-content/uploads/2021/05/Untitled-41.png)

ds\_group Active Directory WMI attribute

3\. Now, run [`Get-CimInstance`](https://docs.microsoft.com/en-us/powershell/module/cimcmdlets/get-ciminstance?view=powershell-7.1) to find all instances of the `ds_group` class which will return the `cn` property of each group.

```powershell
Get-CimInstance -Namespace 'root\directory\ldap' -ClassName ds_group | Select-Object -Property DS_cn
```

![All AD groups in the ds\_group WMI class](https://adamtheautomator.com/wp-content/uploads/2021/05/Untitled-42.png)

All AD groups in the ds\_group WMI class

## Creating a WMI Event Subscription

Now that you know where to find the groups in WMI, the next step is set up a WMI event subscription to “listen” for changes to those WMI instances. To monitor for a specific event (like a change to an Active Directory group), you must _subscribe_ to the WMI event.

You can subscribe to many different types of WMI events from creation, removal, and modification events. In this case, you need to know when a CIM instance (AD group) is modified. In that case, you’ll use a class named `CIM_InstModification`**.** The `CIM_InstModification` class monitors any CIM instance for modifications.

### Develop the WQL Query

To set up the WMI event subscription, you must first develop a [WQL query](https://docs.microsoft.com/en-us/windows/win32/wmisdk/wql-sql-for-wmi). WQL is a simple language dedicated to WMI that allows you to find WMI instances in a SQL-like syntax. In this example, the query you’re looking for looks like the below example.

The below WQL query will look for all events that modify instances matching the name of `DS_group`. You’ll also notice the [`within` operator](https://docs.microsoft.com/en-us/windows/win32/wmisdk/within-clause). This operator is the polling interval telling Windows to check for new events every 10 seconds.

```sql
Select * from CIM_InstModification within 10 where TargetInstance ISA 'DS_group'
```

> _You can also query for changes to specific AD groups by including more conditions such as adding `AND TargetInstance.ds_cn='Enterprise Admins'` to the end of your WQL statement._

### Create the WMI Subscription in PowerShell

Now that you’ve crafted the WQL query, the next step is to drop into PowerShell and use it to subscribe to the event. To do that:

1\. Open PowerShell on the domain controller.

2\. Create a variable called `$query` assigning the query you just came up with as the value.

```powershell
$query = "Select * from CIM_InstModification within 10 where TargetInstance ISA 'DS_group'"
```

3\. Use that query to create the subscription (register the event) using the [`Register-CimIndicationEvent` cmdlet](https://docs.microsoft.com/en-us/powershell/module/cimcmdlets/register-cimindicationevent?view=powershell-7.1). The below command registers a WMI subscription called `GroupMonitoring` using the query to limit results to only `DS_Group` modification events within the `ROOT\directory\LDAP` namespace.

```powershell
Register-CimIndicationEvent -Query $query -SourceIdentifier 'GroupMonitoring' -MessageData 'Group Info Changed' -Namespace 'ROOT\directory\LDAP'
```

> _`Register-CimIndicationEvent` creates a temporary WMI event subscription. When you close the PowerShell console, the subscription will no longer be active. Use a [permanent event subscription](https://devblogs.microsoft.com/scripting/use-powershell-to-create-a-permanent-wmi-event-to-launch-a-vbscript/) to monitor AD groups long term._

4\. Now, confirm you’ve successfully registered a subscription by running [`Get-EventSubscriber`](https://docs.microsoft.com/en-us/powershell/module/microsoft.powershell.utility/get-event?view=powershell-7.2subscriber?view=powershell-7.1) which should return an object that looks like below.

![The Get-EventSubscriber output.](https://adamtheautomator.com/wp-content/uploads/2021/05/Untitled-43.png)

The Get-EventSubscriber output.

## Reading WMI Events

Windows should now be monitoring all modification events to all Active Directory groups. To test this, let’s now add a member to a group and see what happens.

Assuming you’re still in PowerShell on the DC:

1\. Run the `Add-ADGroupMember` cmdlet to add a user to the Enterprise Admins group. The below example is adding a user account named _User2_.

After 10 seconds or so, the event should have fired you set up a subscription for earlier.

```powershell
Add-ADGroupMember -Identity 'Enterprise Admins' -Members User2
```

2\. To find the event, run the [`Get-Event` cmdlet](https://docs.microsoft.com/en-us/powershell/module/microsoft.powershell.utility/get-event) to search for all newly registered events. If all goes well, you should then see output similar to the below screenshot. In the screenshot, the `SourceInstance` is the current value of the object attribute. The `PreviousInstance` value is the previous value of the object attribute.

```powershell
(Get-Event).SourceEventArgs.newevent
```

![Running Get-Event to see the event.](https://adamtheautomator.com/wp-content/uploads/2021/05/Untitled-44.png)

Running Get-Event to see the event.

3\. Now, narrow down the result and only display the current alert values as shown below. You will now see the current list of group members in the Enterprise Admins group.

```powershell
(Get-Event).SourceEventArgs.newevent.SourceInstance | Select-Object -Property ds_member
```

![The current value of the Enterprise Admins Group ](https://adamtheautomator.com/wp-content/uploads/2021/05/Untitled-45.png)

The current value of the Enterprise Admins Group

If you’d like to get the value _before_ the change happened, look at the `PreviousInstance` object’s `DS_Member` property as shown below.

```powershell
(Get-Event).SourceEventArgs.newevent.PreviousInstance | select DS_member
```

![Previous Instance](https://adamtheautomator.com/wp-content/uploads/2021/05/Untitled-46.png)

Previous Instance

## Conclusion

Now that you know how to set up a WMI event subscription to track Active Directory changes, you can take this PowerShell code and build a monitoring script from it.

See if you can now build a monitoring tool by perhaps logging these events to the Windows event log with the [`New-WinEvent` cmdlet](https://docs.microsoft.com/en-us/powershell/module/microsoft.powershell.diagnostics/new-winevent?view=powershell-7.1) or sending an email with [`Send-MailMessage`](https://adamtheautomator.com/send-mailmessage/)!

Share this article

[Share on X](https://twitter.com/intent/tweet?url=https%3A%2F%2Fadamtheautomator.com%2Ftrack-active-directory-changes%2F&text=How%20to%20Track%20Active%20Directory%20Changes%20with%20WMI%20Events)[Share on Facebook](https://www.facebook.com/sharer/sharer.php?u=https%3A%2F%2Fadamtheautomator.com%2Ftrack-active-directory-changes%2F)[Share on LinkedIn](https://www.linkedin.com/sharing/share-offsite/?url=https%3A%2F%2Fadamtheautomator.com%2Ftrack-active-directory-changes%2F)

## Related Posts

![](https://adamtheautomator.com/wp-content/uploads/2026/05/featured_image-11.webp)

### [How to Troubleshoot Active Directory Replication Errors](/troubleshoot-active-directory-replication-errors/)

Troubleshoot Active Directory replication errors by isolating 1311, 1722, 2087, and USN rollback issues with repadmin, dcdiag, DNS, RPC, and KCC checks.

![](https://adamtheautomator.com/wp-content/uploads/2026/05/featured_image-7.webp)

### [Migrate Group Policy to Intune Without Breaking Endpoints](/gpo-intune-migration/)

Export GPOs as XML, analyze them with Group Policy Analytics, migrate supported settings to Intune Settings Catalog, and resolve hybrid device conflicts.

![](https://adamtheautomator.com/wp-content/uploads/2026/06/ditch-gpos-intune-featured.webp)

### [Ditch the GPOs: Migrate to Microsoft Intune](/ditch-gpos-migrate-microsoft-intune-2/)

Use Group Policy Analytics to migrate GPOs to Intune Settings Catalog profiles, handle unsupported Group Policy Preferences, and manage hybrid AD-to-MDM transitions.

## Categories

*   [IT Ops](/category/it-ops/)
*   [Cloud](/category/cloud/)
*   [DevOps](/category/devops/)
*   [Home Ops](/category/home-ops/)
*   [Information Security](/category/infosec/)
*   [Software Development](/category/software-development/)

## Site

*   [Home](/)
*   [Tutorials](/tutorials/)
*   [Instructors](/author/)
*   [Advertising](/advertising/)
*   [Recommended Resources](/resources/)
*   [About Adam](/about-adam/)

Copyright 2026© ATA Learning | [Privacy Policy](/privacy/)
