Configuring Audit Polices for Active Directory auditing:
- Open Group Policy Management Console(GPMC).
- Edit “Default Domain Controllers Policy”.
- Configure required,
- Advanced Audit Policies(2k8 and above): Configuration|Windows Settings|Security Settings|Advanced Audit Policy Configuration|System Audit Policies.
- Audit Polices(2k3 and below) : Computer Configuration|Windows Settings|Security Settings|Local Polices|Audit Policy.
- Advanced Audit Polices required for Active Directory auditing (recommended for 2k8 and above Domain Controllers)
- Audit Logon Events: Select Account Logon -> Audit 'Kerberos Authentication Service' (Success & Failure).
- Audit User, Group, Computer: Select Account Management -> Audit 'Computer Account Management' (Success), Audit 'Distribution Group Management' (Success), Audit 'Security Group Management' (Success), Audit 'User Account Management' (Success & Failure).
- Audit Tracking Processes: Select Detailed Tracking -> Audit Process Creation (Success), Audit Process Termination (Success).
- Audit GPO, OU, Configuration, Schema, Contacts, Containers, Sites, DNS: Select DS Access -> Audit Directory Services Changes (Success), Audit Directory Service Access (Success).
- Audit Logon / Logoff: Select Logon / Logoff -> Audit Logon (Success & Failure), Audit Logoff (Success), Audit Network Policy Server (Success & Failure), Audit Other Logon / Logoff Events (Success).
- Audit Scheduled Tasks: Select Object Access -> Audit Other Object Access Events (Success).
- Audit Local Policy Changes: Select Policy Change -> Audit Authentication Policy Change (Success), Audit Authorization Policy Change (Success).
- Audit System Events: Select System -> Audit Security State Change (Success).

- Audit Polices required for Active Directory Auditing (Recommend for 2k3 and below Domain Controllers)-
- Audit Account Logon: Configure Account Logon Events (Success & Failure).
- Audit Logon / Logoff: Configure Logon Events (Success & Failure).
- Audit User, Group, Computer: Configure Account Management (Success & Failure).
- Audit GPO, OU, Configuration, Schema, Contacts, Containers, Site: Configure Directory Service Access (Success).
- Audit Tracking Processes: Configure Process Tracking (Success).
- Audit Scheduled Tasks: Configure Object Access (Success).
- Audit Local Policy Changes: Configure Policy Change (Success).
- Audit System Events: Configure System Events (Success).

- Force Advanced Audit Policy
- Enable Force audit policy subcategory settings. This settings can be found under Computer Configuration|Windows Settings|Security Settings|Local Polices|Security Options|Audit: Force audit policy subcategory settings (Windows Vista or later) to override audit policy category settings.

Copyright © 2023,
ZOHO Corp.
All Rights Reserved.
Get download link