Skip to content

Active Directory Audit Policies

Active Directory audit policies must be configured to ensure events are logged when activity occurs. The steps below walk through the audit policy settings that need to be enabled.

Active Directory Audit Policy Configuration

Section titled “Active Directory Audit Policy Configuration”

Step 1: Open the Group Policy Management Console (GPMC)

Step 2: Right click “Default Domain Controllers Policy” and select edit.

Step 3: Under Computer Configuration, click Policies > Windows Settings > Security Settings > Advanced Audit Policy Configuration > Audit Policy

advanced audit policy configuration

Step 4: Configure the audit policies based on the table below

Advanced Audit Policy Settings for AD Audit Pro

Section titled “Advanced Audit Policy Settings for AD Audit Pro”
Policy PathPolicy Settings NameAudit Event Settings
Account ManagementAudit Computer Account ManagementSuccess
Account ManagementAudit Security Group ManagementSuccess
Account ManagementAudit User Account ManagementSuccess and Failure
DS AccessAudit Directory Service ChangesSuccess
Logon/LogoffAudit Account LockoutFailure
Logon/LogoffAudit LogonSuccess and Failure
Policy ChangeAudit Audit Policy ChangeSuccess

Configure Active Directory Object Level Auditing

Section titled “Configure Active Directory Object Level Auditing”

There are specific events that do not generate an audit log entry until object level auditing is enabled.

AD Audit Pro require object level auditing

  • Moved users
  • Moved groups
  • Moved computers
  • Deleted GPOs
  • GPO Link Changes
  • Created OUs
  • Deleted OUs

Advanced Features must be enabled in ADUC to complete the steps. Click on “View” and then “Advanced Features”.

enabled advanced features

Step 1. Open ADUC, right click on your domain and select properties.

click on domain properties

Step 2. Click on “Security”

click on security

Step 3. Click on “Advanced”

click on advanced

Step 4. Click on “Auditing”

click on auditing

Step 5. Click on “Add”

click on Add

Step 6. Click on “Select a Principal”

click on select a principal

Step 7. Type Everyone, click “Check Names” and click “OK”.

enter everyone

Step 8. Ensure Type = Success and Appplies to = This object and all descent objects

enter everyone

Step 9. Set the following Permissions:

  1. Write All Properties
  2. Delete
  3. Modify Permissions
  4. All Extended Rights
  5. Create user objects
  6. Delete user objects
  7. Create Group objects
  8. Delete Group objects
  9. Create computer objects
  10. Delete computer objects
  11. Create Organizational Unit objects
  12. Delete Organizational Unit objects
  13. Create groupPolicyContainer Objects
  14. Delete groupPolicyContainer Objects

Example screenshot

select permissions