Configure Active Directory Object Level Auditing
There are specific events that do not generate an audit log entry until object level auditing is enabled.
Entralyzer Reports that require object level auditing
- Moved users
- Moved groups
- Moved computers
- Deleted GPOs
- GPO Link Changes
- Created OUs
- Deleted OUs
How to Enable Object Level Auditing
Section titled “How to Enable Object Level Auditing”Advanced Features must be enabled in ADUC to complete the steps. Click on “View” and then “Advanced Features”.
Step 1. Open ADUC, right click on your domain and select properties.
Step 2. Click on “Security”
Step 3. Click on “Advanced”
Step 4. Click on “Auditing”
Step 5. Click on “Add”
Step 6. Click on “Select a Principal”
Step 7. Type Everyone, click “Check Names” and click “OK”.
Step 8. Ensure Type = Success and Appplies to = This object and all descent objects
Step 9. Set the following Permissions:
- Write All Properties
- Delete
- Modify Permissions
- All Extended Rights
- Create user objects
- Delete user objects
- Create Group objects
- Delete Group objects
- Create computer objects
- Delete computer objects
- Create Organizational Unit objects
- Delete Organizational Unit objects
- Create groupPolicyContainer Objects
- Delete groupPolicyContainer Objects
Example screenshot