{"id":2704,"date":"2017-09-01T23:42:18","date_gmt":"2017-09-01T23:42:18","guid":{"rendered":"http:\/\/pariswells.com\/blog\/?p=2704"},"modified":"2017-09-01T23:42:18","modified_gmt":"2017-09-01T23:42:18","slug":"how-to-enable-active-directory-auditing","status":"publish","type":"post","link":"https:\/\/pariswells.com\/blog\/research\/how-to-enable-active-directory-auditing","title":{"rendered":"How to Enable Active Directory Auditing"},"content":{"rendered":"<h3>Edit the Group Policy that is applying to your domain controllers<\/h3><p><strong>Server 2003<\/strong><\/p><p>Computer Configuration-&gt;Policies-&gt;Windows Settings-&gt;Security Settings-&gt;Local Policies-&gt;Audit Policy\u00a0<\/p><p>-&gt; Enable Audit Directory Access Service<\/p><p><strong>Server 2008 or Above<\/strong><\/p><p>Computer Configuration-&gt;Policies-&gt;Windows Settings-&gt;Security Settings-&gt;Local Policies-&gt;Security Options-&gt;Audit: Force audit policy subcategory settings<\/p><p>Computer Configuration-&gt;Policies-&gt;Windows Settings-&gt;Security Settings-&gt;Advanced Audit Policy Configuration-&gt;Audit Policies-&gt;DS Access<\/p><p><img decoding=\"async\" src=\"http:\/\/www.open-a-socket.com\/wp-content\/uploads\/2014\/07\/14.jpg\" alt=\"14\" \/><\/p><p id=\"YIjiOtg\">\u00a0<\/p><p>&nbsp;<\/p><p><strong>Target OU or Whole Domain<\/strong><\/p><p>Right-click on where you want to enable Auditing and bring up the properties.\u00a0 Under Extensions you will see the Security tab.\u00a0 From there select Advanced and then choose the Auditing tab.\u00a0 If you want to be comprehensive, I would select the Everyone security principal, set Type to Success and Applies to: This object and all descendant objects.\u00a0 For the permissions, again if you want to be comprehensive, set the following:<\/p><ul><li>Write all properties<\/li><li>Delete<\/li><li>Delete subtree<\/li><li>Modify permissions<\/li><li>Modify owner<\/li><li>All validated writes<\/li><li>All extended writes<\/li><li>Create all child objects<\/li><li>Delete all child objects<\/li><\/ul><p><strong>Open Event viewer and filter Security log to find event id\u2019s (Windows Server 2003\/2008-2012): <\/strong><br \/>&#8211; 631, 635, 648, 653, 658, 663\/4727, 4731, 4754 , 4759, 4744, 4749 \u2013 Group created <br \/>&#8211; 632, 636, 650, 655, 660, 665\/4728, 4732, 4756 , 4761, 4746, 4751 \u2013 Member added to a group <br \/>&#8211; 633, 637, 651, 656, 661, 666\/4729, 4733, 4757, 4762, 4747, 4752 \u2013 Member removed from a group <br \/>&#8211; 634, 638, 652, 662, 667, 657\/4730, 4734, 4758, 4748, 4753, 4763 \u2013 Group deleted <br \/>&#8211; 639, 641, 649, 654, 659, 664\/4735, 4737, 4745, 4750, 4755, 4760 \u2013 Group changed <br \/>&#8211; 566\/4662 &#8211; An operation was performed on an object(OU Changes) (Type: Directory Service Access).<\/p>","protected":false},"excerpt":{"rendered":"<p>Edit the Group Policy that is applying to your domain controllersServer 2003Computer Configuration-&gt;Policies-&gt;Windows Settings-&gt;Security Settings-&gt;Local Policies-&gt;Audit Policy\u00a0-&gt; Enable Audit Directory Access ServiceServer 2008 or AboveComputer Configuration-&gt;Policies-&gt;Windows Settings-&gt;Security [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[1],"tags":[750,2065,2067,2068,1677,2069,2066],"class_list":["post-2704","post","type-post","status-publish","format-standard","hentry","category-research","tag-active-directory","tag-ad-audit","tag-auditing","tag-changes-to-ad","tag-domain-controller","tag-ds-audit","tag-ou"],"aioseo_notices":[],"_links":{"self":[{"href":"https:\/\/pariswells.com\/blog\/wp-json\/wp\/v2\/posts\/2704","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/pariswells.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/pariswells.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/pariswells.com\/blog\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/pariswells.com\/blog\/wp-json\/wp\/v2\/comments?post=2704"}],"version-history":[{"count":2,"href":"https:\/\/pariswells.com\/blog\/wp-json\/wp\/v2\/posts\/2704\/revisions"}],"predecessor-version":[{"id":2716,"href":"https:\/\/pariswells.com\/blog\/wp-json\/wp\/v2\/posts\/2704\/revisions\/2716"}],"wp:attachment":[{"href":"https:\/\/pariswells.com\/blog\/wp-json\/wp\/v2\/media?parent=2704"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/pariswells.com\/blog\/wp-json\/wp\/v2\/categories?post=2704"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/pariswells.com\/blog\/wp-json\/wp\/v2\/tags?post=2704"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}