Skip to content

Configure Active Directory Object Level Auditing

There are specific events that do not generate an audit log entry until object level auditing is enabled.

Entralyzer Reports that require object level auditing

  • Moved users
  • Moved groups
  • Moved computers
  • Deleted GPOs
  • GPO Link Changes
  • Created OUs
  • Deleted OUs

Advanced Features must be enabled in ADUC to complete the steps. Click on “View” and then “Advanced Features”.

enabled advanced features

Step 1. Open ADUC, right click on your domain and select properties.

click on domain properties

Step 2. Click on “Security”

click on security

Step 3. Click on “Advanced”

click on advanced

Step 4. Click on “Auditing”

click on auditing

Step 5. Click on “Add”

click on Add

Step 6. Click on “Select a Principal”

click on select a principal

Step 7. Type Everyone, click “Check Names” and click “OK”.

enter everyone

Step 8. Ensure Type = Success and Appplies to = This object and all descent objects

enter everyone

Step 9. Set the following Permissions:

  1. Write All Properties
  2. Delete
  3. Modify Permissions
  4. All Extended Rights
  5. Create user objects
  6. Delete user objects
  7. Create Group objects
  8. Delete Group objects
  9. Create computer objects
  10. Delete computer objects
  11. Create Organizational Unit objects
  12. Delete Organizational Unit objects
  13. Create groupPolicyContainer Objects
  14. Delete groupPolicyContainer Objects

Example screenshot

select permissions