Skip to content

Commit 42ab8c2

Browse files
committed
acrolinx fixes
1 parent b1fdfa1 commit 42ab8c2

File tree

1 file changed

+5
-5
lines changed

1 file changed

+5
-5
lines changed

defender-for-identity/advanced-configurations.md

Lines changed: 5 additions & 5 deletions
Original file line numberDiff line numberDiff line change
@@ -1,6 +1,6 @@
11
---
2-
title: Configure audit policies for Windows event logs | Microsoft Defender for Identity
3-
description: This article describes how to configure audit policies for Windows event logs as part of deploying a Microsoft Defender for Identity sensor.
2+
title: Configure advandced settings | Microsoft Defender for Identity
3+
description: This article describes how to configure advanced settings of deploying a Microsoft Defender for Identity sensor.
44
ms.date: 11/05/2025
55
ms.topic: how-to
66
ms.reviewer: rlitinsky
@@ -10,7 +10,7 @@ ms.reviewer: rlitinsky
1010

1111
## Automatic Windows event auditing (Preview)
1212

13-
Defender for Identity detections rely on specific Windows event log entries to enhance detections and provide extra information about the users performing specific actions, such as NTLM sign-ins and security group modifications.
13+
Defender for Identity uses specific Windows event log entries to enhance detections and provide extra information about the users performing specific actions, such as NTLM sign-ins and security group modifications.
1414
This article describes how to configure the advanced audit policy settings to avoid gaps in the event logs and incomplete Defender for Identity coverage.
1515

1616
Defender for Identity generates health issues when it detects incorrect windows event auditing configurations. For more information, see [Microsoft Defender for Identity health alerts](../health-alerts.md).
@@ -31,7 +31,7 @@ When automatic windows event auditing is enabled, it:
3131
- Configures local Windows audit policy using Windows Local Security Authority (LSA) audit policy APIs.
3232
- Sends health alerts about the configuration state.
3333

34-
If you do not select automatic Windows auditing configuration, you must [manually configure Windows event auditing](configure-windows-event-collection.md) in the Defender portal or using PowerShell.
34+
If you don't select automatic Windows auditing configuration, you must [manually configure Windows event auditing](configure-windows-event-collection.md) in the Defender portal or using PowerShell.
3535

3636
### Enable Automatic Windows event auditing
3737

@@ -41,7 +41,7 @@ To turn on automatic windows auditing:
4141
1. Turn on **Automatic Windows auditing configuration**.​
4242

4343
## Disable Automatic Windows event auditing
44-
When you turn off automatic windows auditing, Defender for Identity stops checking and applying the required audit settings on your domain controllers. Any configurations that were applied by automatic windows auditing remain unchanged.
44+
When you turn off automatic windows auditing, Defender for Identity stops checking and applying the required audit settings on your domain controllers. Any configurations applied by automatic windows auditing remain unchanged.
4545

4646
To turn off automatic windows auditing:
4747
1. In the [Microsoft Defender portal](https://security.microsoft.com), go to **Settings**, and then **Identities**.

0 commit comments

Comments
 (0)