How to Find an IP Address for a User in an Active Directory

by Nina Rotz

Active Directory is a Microsoft-created database that is used to manage a large number of users, also referred to as domains. The Active Directory runs on a Windows server and is used by server administrators to manage the system and keep security logs of every event on the company's computers. Every computer user has an Internet Protocol, or IP, address. Server administrators use Active Directory security logs to see who logged in, when they logged in and what files they accessed.

1

Login to your Windows server that is running Active Directory using the administrator username and password.

2

Click "Start" and select "Administrative Tools."

3

Click on "Event Viewer." A new window will launch.

4

Click on "Security Log" in the left pane. You will see a list of security log events, such as Active Directory users logging in the system, accessing files and modifying their account settings. Each event or login session will have its own log file. IP addresses are stored in the Account Logon category.

5

Right-click on the "Success Audit" log in the Account Logon category. Select "Open" from the menu. This log will open in a new window.

6

Browse through the opened file. You will see the username that logged on, as well as the time and date this even occurred. The last line labeled "Client Address" is the user's IP address. This is the IP address that accessed Active Directory and logged into the system.

Photo Credits

  • photo_camera Computer servers skyline image by patrimonio designs from Fotolia.com