1. Configure advanced audit policies
Advanced audit policies help administrators exercise granular control over which activities get recorded in the logs, helping reduce event noise. We recommend configuring advanced audit policies on Windows Server 2008 and above.
- Log in to any computer that has the Group Policy Management Console (GPMC) with Domain Admin credentials.
- Open the GPMC and, based on your setup, right-click Default Domain Controllers Policy or ADAuditPlusMSPolicy or ADAuditPlusWSPolicy, and select Edit.
Note: For the appropriate group policy, refer to the table below:
- In the Group Policy Management Editor, go to Computer Configuration > Policies > Windows Settings > Security Settings > Advanced Audit Policy Configuration, and configure the following settings:
Category |
Subcategory |
Audit events |
Purpose |
Object Access |
- Audit File System
- Audit File Share
- Audit Handle Manipulation
|
- Success, Failure
- Success
- Success, Failure
|
|
Policy Change |
- Audit Policy Change
- Authorization Policy Change
|
|
- File permission change auditing
|