Skip to content

Commit 07aa2a3

Browse files
committed
removed automatic windows auditing
1 parent a0cd527 commit 07aa2a3

File tree

3 files changed

+90
-81
lines changed

3 files changed

+90
-81
lines changed
Lines changed: 60 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,60 @@
1+
---
2+
title: Configure audit policies for Windows event logs | Microsoft Defender for Identity
3+
description: This article describes how to configure audit policies for Windows event logs as part of deploying a Microsoft Defender for Identity sensor.
4+
ms.date: 11/05/2025
5+
ms.topic: how-to
6+
ms.reviewer: rlitinsky
7+
---
8+
9+
# Microsoft Defender for Identity advanced configurations
10+
11+
## Automatic Windows event auditing (Preview)
12+
13+
Defender for Identity detections rely on specific Windows event log entries to enhance detections and provide extra information about the users performing specific actions, such as NTLM sign-ins and security group modifications.
14+
This article describes how to configure the advanced audit policy settings to avoid gaps in the event logs and incomplete Defender for Identity coverage.
15+
16+
Defender for Identity generates health issues when it detects incorrect windows event auditing configurations. For more information, see [Microsoft Defender for Identity health alerts](../health-alerts.md).
17+
18+
Defender for Identity sensor v3.x supports automatic Windows event auditing on your domain controllers. This feature applies the required Windows event auditing settings to new sensors and fixes misconfigurations on existing ones.
19+
20+
Automatic windows event auditing runs periodically to check and maintain proper audit settings on your Domain Controllers.
21+
22+
When automatic windows event auditing is enabled, it:
23+
24+
- Checks current audit configuration, and verifies that the current configurations are correct.
25+
- Identifies gap and determines what's missing or needs adjustment.
26+
- Applies changes to settings that aren't properly set, leaving existing configurations intact.
27+
- Adds audit entries to the domain root object's System Access Control List (SACL) to enable required directory service auditing.
28+
- Adds audit entries to the object's System Access Control List (SACL) of the AD FS configuration container, to enable auditing of AD FS-related directory objects.
29+
- Modifies the SACL on the Configuration partition to capture changes to directory service configuration objects.
30+
- Uses standard Windows Registry APIs to configure the required NTLM auditing registry values.
31+
- Configures local Windows audit policy using Windows Local Security Authority (LSA) audit policy APIs.
32+
- Sends health alerts about the configuration state.
33+
34+
If you do not select automatic Windows auditing configuration, you must [manually configure Windows event auditing](configure-windows-event-collection.md) in the Defender portal or using PowerShell.
35+
36+
### Enable Automatic Windows event auditing
37+
38+
To turn on automatic windows auditing:
39+
1. In the [Microsoft Defender portal](https://security.microsoft.com), go to **Settings**, and then **Identities**.
40+
1. In the **General** section, select **Advanced features**.
41+
1. Turn on **Automatic Windows auditing configuration**.​
42+
43+
## Disable Automatic Windows event auditing
44+
When you turn off automatic windows auditing, Defender for Identity stops checking and applying the required audit settings on your domain controllers. Any configurations that were applied by automatic windows auditing remain unchanged.
45+
46+
To turn off automatic windows auditing:
47+
1. In the [Microsoft Defender portal](https://security.microsoft.com), go to **Settings**, and then **Identities**.
48+
1. In the **General** section, select **Advanced features**.
49+
1. Turn off **Automatic Windows auditing configuration**.​
50+
51+
52+
53+
- [Event collection with Microsoft Defender for Identity](event-collection-overview.md)
54+
- [Windows security auditing](/windows/security/threat-protection/auditing/security-auditing-overview)
55+
- [Advanced security audit policies](/windows/security/threat-protection/auditing/advanced-security-auditing)
56+
57+
## Next step
58+
59+
> [!div class="step-by-step"]
60+
> [What are Defender for Identity roles and permissions?](../role-groups.md)

0 commit comments

Comments
 (0)