In addition to configuring the Default Domain Controllers policy which allows to audit "Account Logon Events", "Account Management events", "Directory Service access" and "Logon Events" in the Domain, ADAudit Plus also allows one to audit local changes on the Domain Controllers. Local Changes on Domain Controllers listed below will be recorded in the security logs of respective servers depending upon the type of audit policy configured.
Process starts or exits?
Audit Policy changes?
User Rights Assigned / Removed for users?
User Rights Assigned / Removed for groups?
Security Access Assigned / Removed for users?
Security Access Assigned / Removed for groups?
System time is changed?
Scheduled Task is Created/Modified/Deleted?
Local Account is Changed (Local Account Management - Users/Groups)?
Audit Policy Required for recording "Local Changes on Domain Controllers" in the Security logs:
To view reports on the above listed events corresponding audit policies are to be configured in the Member Servers. The Audit Policies to be configured include
Log on to Windows with an account that has Administrator rights.
Ensure that the Group Policy snap-in is installed.
Open the GPMC (Group Policy Management Console).
Edit the GPO that is applied on all selected Member Servers (How to select Member Servers) that require audit reporting.
Click on the "Group Policy Object" and click on "Edit"
This will direct you to "Group Policy Management Editor"
Navigate to "Audit Policy" node,
"Computer Configuration -> Windows Settings -> Security Settings -> Local Policies -> Audit Policy"