Configuring Audit Polices for Active Directory auditing:
- Open Group Policy Management Console(GPMC).
- Edit “Default Domain Controllers Policy”.
- Configure required,
- Advanced Audit Policies(2k8 and above) :
Configuration|Windows Settings|Security Settings|Advanced
Audit Policy Configuration|System Audit Policies.
- Audit Polices(2k3 and below) : Computer
Configuration|Windows Settings|Security Settings|Local
Polices|Audit Policy.
- Advanced Audit Polices required for Active Directory
auditing (recommended for 2k8 and above Domain Controllers)
- Audit Logon Events: Select Account Logon -> Audit
'Kerberos Authentication Service' (Success & Failure).
- Audit User, Group, Computer: Select Account Management
-> Audit 'Computer Account Management' (Success), Audit
'Distribution Group Management' (Success), Audit 'Security
Group Management' (Success), Audit 'User Account Management'
(Success & Failure).
- Audit Tracking Processes: Select Detailed Tracking ->
Audit Process Creation (Success), Audit Process Termination
(Success).
- Audit GPO, OU, Configuration, Schema, Contacts,
Containers, Sites, DNS: Select DS Access -> Audit
Directory Services Changes (Success), Audit Directory
Service Access (Success).
- Audit Logon / Logoff: Select Logon / Logoff -> Audit
Logon (Success & Failure), Audit Logoff (Success), Audit
Network Policy Server (Success & Failure), Audit Other
Logon / Logoff Events (Success).
- Audit Scheduled Tasks: Select Object Access -> Audit
Other Object Access Events (Success).
- Audit Local Policy Changes: Select Policy Change ->
Audit Authentication Policy Change (Success), Audit
Authorization Policy Change (Success).
- Audit System Events: Select System -> Audit Security
State Change (Success).

- Audit Polices required for Active Directory Auditing
(Recommend for 2k3 and below Domain Controllers)-
- Audit Account Logon: Configure Account Logon Events
(Success & Failure).
- Audit Logon / Logoff: Configure Logon Events (Success
& Failure).
- Audit User, Group, Computer: Configure Account Management
(Success & Failure).
- Audit GPO, OU, Configuration, Schema, Contacts,
Containers, Site: Configure Directory Service Access
(Success).
- Audit Tracking Processes: Configure Process Tracking
(Success).
- Audit Scheduled Tasks: Configure Object Access (Success).
- Audit Local Policy Changes: Configure Policy Change
(Success).
- Audit System Events: Configure System Events (Success).
- Force Advanced Audit Policy
- Enable Force audit policy subcategory settings. This
settings can be found under Computer
Configuration|Windows Settings|Security Settings|Local
Polices|Security Options|Audit: Force audit policy
subcategory settings (Windows Vista or later) to override
audit policy category settings.
Copyright © 2017,
ZOHO Corp.
All Rights Reserved.