Configure audit policies in your domain - Manual configuration

Audit policies must be configured to log events whenever any activity occurs.

For module logging

  • Log in to any computer that has the Group Policy Management Console (GPMC) with domain admin credentials. 
  • Open the GPMC and, based on your setup, edit the:
    • Default Domain Controllers Policy to enable module logging on a DC.
    • ADAuditPlusMSPolicy to enable module logging on a Windows server.
  • In the Group Policy Management Editor, go to Computer Configuration > Policies > Administrative Templates > Windows Components > Windows Powershell. Navigate to the right pane, and right-click on Turn on Module Logging > Enabled.
  • In the Options pane, click on Show. In the Module Names window, enter * to record all modules, and press OK.
Configure audit policies in your domain in ADAudit Plus

For script block logging

  • Log in to any computer that has the GPMC with domain admin credentials. 
  • Open the GPMC and, based on your setup, edit the:
    • Default Domain Controllers Policy to enable module logging on a DC.
    • ADAuditPlusMSPolicy to enable module logging on a Windows server.
  • In the Group Policy Management Editor, go to Computer Configuration > Policies > Administrative Templates > Windows Components > Windows Powershell. Navigate to the right pane, and right-click on Turn on PowerShell Script Block Logging > Enabled.
Configure audit policies in your domain in ADAudit Plus

我们的客户