Configuring Audit Policy to audit changes on Domain Controllers

 

In addition to configuring the Default Domain Controllers policy which allows to audit "Account Logon Events", "Account Management events", "Directory Service access" and "Logon Events" in the Domain, ADAP also allows one to audit local changes on the Domain Controllers. Local Changes on Domain Controllers listed below will be recorded in the security logs of respective servers depending upon the type of audit policy configured.

 

What changes are recorded in the Server?

Audit Policy Required for recording "Local Changes on Domain Controllers" in the Security logs:

 

To view reports on the above listed events corresponding audit policies are to be configured in the Member Servers. The Audit Policies to be configured include

  1. Audit Policy Change - Success / Failure.

  2. Audit Process Tracking - Success.

  3. Audit System Events - Success / Failure.

  1. Log on to Windows with an account that has Administrator rights.

  2. Ensure that the Group Policy snap-in is installed.

  3. Open the GPMC (Group Policy Management Console).

  4. Edit the GPO that is applied on all selected Member Servers (How to select Member Servers) that require audit reporting.

  5. Click on the "Group Policy Object" and click on "Edit"

  6. This will direct you to "Group Policy Management Editor"

  7. Navigate to "Audit Policy" node,

"Computer Configuration -> Windows Settings -> Security Settings -> Local Policies -> Audit Policy"

  1. Configure

  1. Audit Policy Change - Success / Failure.

  2. Audit Process Tracking - Success.

  3. Audit System Events - Success / Failure.

 

 

© 2017 卓豪(中国)技术有限公司,保留一切权利