ADAudit Plus provides five predefined audit reports, each providing detailed insights into password life cycle operations for legacy and Windows LAPS, enabling administrators to track password reads, expiry changes, and critical security events.
Feature |
Audited event |
Attributes read |
Legacy LAPS |
LAPS Password Read |
ms-Mcs-AdmPwd |
LAPS Password Expiry Changes |
ms-Mcs-AdmPwdExpirationTime |
Windows LAPS |
Windows LAPS Password Read |
ms-LAPS-Password |
Windows LAPS Password Expiry Changes |
ms-LAPS-PasswordExpirationTime |
DSRM Password Read |
ms-LAPS-EncryptedDSRMPasswordHistory, ms-LAPS-EncryptedDSRMPassword, ms-LAPS-EncryptedPasswordHistory, ms-LAPS-EncryptedPassword |