Configure audit policies in your domain - Manual Process
Configure advanced audit policies
Advanced audit policies help administrators exercise granular control over which activities get recorded in the logs, helping reduce event noise. We recommend configuring advanced audit policies on Windows Server 2008 and above.
Force advanced audit policies
When using advanced audit policies, ensure they are forced over legacy audit policies.
- Log in to any computer that has the GPMC with Domain Admin credentials.
- Open the GPMC and, based on your setup, right-click Default Domain Controllers Policy or ADAuditPlusMSPolicy or ADAuditPlusWSPolicy, then select Edit.
- In the Group Policy Management Editor, go to Computer Configuration > Policies > Windows Settings > Security Settings > Local Policies > Security Options.
- Right-click Audit: Force audit policy subcategory settings from the right pane.
- Select Properties, then choose Enabled.
Configure legacy audit policies
Due to the unavailability of advanced audit policies in Windows Server 2003 and earlier versions, legacy audit policies need to be configured for these types of servers.
- Log in to any computer that has the GPMC with Domain Admin credentials.
- Open the GPMC and, based on your setup, right-click Default Domain Controllers Policy or ADAuditPlusMSPolicy or ADAuditPlusWSPolicy, then select Edit.
- In the Group Policy Management Editor, go to Computer Configuration > Policies > Windows Settings > Security Settings > Local Policies.
- Double-click Audit Policy.
- Right-click on the Object Access policy in the right pane.
- Select Properties, then check the box next to Success.
Don't see what you're looking for?
-
Visit our community
Post your questions in the forum.
-
Request additional resources
Send us your requirements.
-
Need implementation assistance?
Try OnboardPro