- Related Products
- ADManager Plus
- ADSelfService Plus
- EventLog Analyzer
- Exchange Reporter Plus
- AD360
- Log360
The Amazon FSx file system can be used with either a self-managed Microsoft Active Directory (AD) or an AWS Managed Microsoft AD.
If you are using your Amazon FSx file system with a self-managed Microsoft AD and have assigned sufficient privileges to the user configured under Domain Settings, ADAudit Plus automatically configures the required audit policies when you add your file system for auditing. Otherwise, you can configure the audit policies manually by following the steps under Manual audit policy configuration.
If you are using your Amazon FSx file system with an AWS Managed Microsoft AD, follow the steps under Manual audit policy configuration to configure the required audit policies.
Configure the list of Amazon FSx Windows file systems to be audited:
Note: The GPMC will not be installed on workstations and/or enabled on member servers by default, so we recommend configuring audit policies on Windows domain controllers. Otherwise, follow the steps in this page to install GPMC on your desired member server or workstation.
In the GPMC, right-click the domain in which you want to configure the Group Policy. Select Create a GPO and Link it here. In the New GPO window that opens, type in “ADAuditPlusFSPolicy” and click OK.
In the GPMC, right-click the OU with the same name as your domain (the OU created by AWS that you have 'Edit' access for). Select Create a GPO and Link it here. In the New GPO window that opens, type in “ADAuditPlusFSPolicy” and click OK
Advanced audit policies help administrators exercise granular control over which activities get recorded in the logs, helping cut down on event noise. We recommend configuring advanced audit policies on Windows Server 2008 and above.
Category | Sub category | Audit events | Purpose |
---|---|---|---|
Object Access |
|
|
File share auditing |
When using advanced audit policies, ensure that they are forced over legacy audit policies.
Due to the unavailability of advanced audit policies in Windows Server 2003 and earlier versions, legacy audit policies need to be configured for these types of servers.
Category | Audit events | Purpose |
---|---|---|
Object Access | Success, Failure |
|