AD Auditing Logs


dear all,

i'm using windows server 2008 r2. i've enabled following 2 policies of default domain controllers gpo.

audit account management  
audit directory service access

but doesn't generate ad related logs in event viewer if changed in ad mmc. i've connfigured sacl on domain root. please 1 me sort this.


thanks , regards, bharath s.

 

  • audit account management:

 

 

this security setting determines whether audit each event of account management on computer. examples of account management events include:

  • a user account or group created, changed, or deleted.
  • a user account renamed, disabled, or enabled.
  • a password set or changed.

if define policy setting, can specify whether audit successes, audit failures, or not audit event type @ all. success audits generate audit entry when account management event succeeds. failure audits generate audit entry when account management event fails. set value to no auditing, in theproperties dialog box policy setting, select the define these policy settings check box , clear thesuccess and failure check boxes.

default:

  • success on domain controllers.
  • no auditing on member servers
for more information events logs generated, refer microsoft article.

  • audit directory service access:

this security setting determines whether audit event of user accessing active directory object has own system access control list (sacl) specified.

by default, value set no auditing in default domain controller group policy object (gpo), , remains undefined workstations , servers has no meaning.

if define policy setting, can specify whether audit successes, audit failures, or not audit event type @ all. success audits generate audit entry when user accesses active directory object has sacl specified. failure audits generate audit entry when user unsuccessfully attempts access active directory object has sacl specified. set value to no auditing, in the properties dialog box policy setting, select the define these policy settings check box , clear the success andfailure check boxes.

for more information, refer microsoft article.

check if have 566 events.

 

if not help, run gupdate /force command , check if problem solved or not.

also make sure gpo linked dcs ou.

 

if problem persists, please check if don't have replication problem. can post output of dcdiag /v command here.

 

 


posting provided "as is" no warranties or guarantees , , confers no rights.

microsoft student partner
microsoft certified professional
microsoft certified systems administrator: security
microsoft certified systems engineer: security
microsoft certified technology specialist: windows server 2008 active directory, configuration
microsoft certified technology specialist: windows server 2008 network infrastructure, configuration

 



 



Windows Server  >  Group Policy



Comments

Popular posts from this blog

Disconnecting from a Windows Server 2012 R2 file sharing session on a Windows 7,8,10 machine

Error: 0x80073701 when trying to add Print Services Role in Windows 2012 Standard

Windows 2016 RDS event 1306 Connection Broker Client failed to redirect the user... Error: NULL