Advanced audit policies help administrators exercise granular control over which activities get recorded in the logs, helping reduce event noise. We recommend configuring advanced audit policies on Windows Server 2008 and above.
| To enable FIM on | Right-click |
|---|---|
| Domain controller | Default Domain Controllers Policy GPO |
| Windows server | ADAuditPlusMSPolicy GPO |
| Workstation | ADAuditPlusWSPolicy GPO |
| Category | Subcategory | Audit events | Purpose |
|---|---|---|---|
| Object Access |
|
|
|
| Policy Change |
|
|
|
When using advanced audit policies, ensure they are forced over legacy audit policies.
| To enable FIM on | Right-click |
|---|---|
| Domain controller | Default Domain Controllers Policy GPO |
| Windows server | ADAuditPlusMSPolicy GPO |
| Workstation | ADAuditPlusWSPolicy GPO |
Due to the unavailability of advanced audit policies in Windows Server 2003 and earlier versions, legacy audit policies need to be configured for these types of servers.
| To enable FIM on | Right-click |
|---|---|
| Domain controller | Default Domain Controllers Policy GPO |
| Windows server | ADAuditPlusMSPolicy GPO |
| Workstation | ADAuditPlusWSPolicy GPO |