Skip to content

Configure Active Directory Audit Policies

Active Directory audit policies must be configured to ensure events are logged when activity occurs. The steps below walk through the audit policy settings that need to be enabled.

Step 1: Open the Group Policy Management Console (GPMC)

Step 2: Righ click “Default Domain Controllers Policy” and select edit.

edit default domain controller policy

Step 3: Under Computer Configuration, click Policies > Windows Settings > Security Settings > Advanced Audit Policy Configuration > Audit Policy

advanced audit policy configuration

Step 4: Configure the audit policies based on the table below

Advanced Audit Policy Settings for Entralyzer

Section titled “Advanced Audit Policy Settings for Entralyzer”
Policy PathPolicy Settings NameAudit Event Settings
Account LogonAudit Credential ValidationFailure
Account LogonAudit Kerberos Authentication ServiceSuccess and Failure
Account LogonAudit Kerberos Service Ticket OperationsFailure
Account ManagementAudit Computer Account ManagementSuccess
Account ManagementAudit Distribution Group ManagementSuccess
Account ManagementAudit Other Account Management EventsSuccess
Account ManagementAudit Security Group ManagementSuccess
Account ManagementAudit User Account ManagementSuccess and Failure
DS AccessAudit Directory Service AccessSuccess
DS AccessAudit Directory Service ChangesSuccess
Logon/LogoffAudit Account LockoutFailure
Logon/LogoffGroup MembershipSuccess
Logon/LogoffAudit LogoffSuccess
Logon/LogoffAudit LogonSuccess and Failure
Logon/LogoffAudit Other Logon/Logoff EventsSuccess and Failure
Logon/LogoffSpecial LogonSuccess
Object AccessAudit Other Object Access EventsSuccess and Failure
Policy ChangeAudit Audit Policy ChangeSuccess
Policy ChangeAudit Authentication Policy ChangeSuccess
Policy ChangeAudit Authorization Policy ChangeSuccess
SystemAudit Securty State ChangeSuccess