I really wish Active Directory was a bit more PubSub. I would love if there was a way to subscribe to an a schema attribute and say, “when this changes for any object that has this attribute, let me know”. But AD’s decentralized model makes that very hard without running a script on every domain controller, running a server to monitor LDAP changes or the least timely, logging everything to a logging platform like Splunk and setting alerts up to tell me hours after it happened… Any other options out there? (And yes I know you can push logs faster but it’s not real-time or even close when you have hundreds of domain controllers).