Hello All,
I have a sever set up with dual purposes and one of them is the SMTP relay someone within the organization went in and made changes to it and all the internal .net apps stop functioning (actually all the apps stopped working but I am only responsible for the web apps), for the time being we switched it back to the old relay server that had not been decommissioned, but one of my .net apps is still not working, not sure why but my real concern and main question is how to I trace back who made the changes (auth mechanism is AD server) updates ran on this server the same day as well but operations says that someone specifically went in and changed the IP settings for the listed range and that is what broken it! So I would like some specific steps to tracing this in the logs or something, any help is appreciated!