Hi,
I have windows 2003 enterprise terminal server and my users access this server for business critical applications.
Yesterday someone played around with those servers and sent message to users that server is going to restart in 15 mins and then server restarted.
I have checked the eventviewer but did not get any events about this activity.
Is there anyway next time if this kind of activity happen then I can cancel shutdown so that in peak time server does not restart it.
Secondly is there any tool which shows who reset users domain password at what time.
I would appreciate if someone assist me as soon as possible.
Thanks and regards,
(Anurag Goswami)