You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Copy file name to clipboardExpand all lines: defender-for-identity/advanced-configurations.md
+5-5Lines changed: 5 additions & 5 deletions
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -1,6 +1,6 @@
1
1
---
2
-
title: Configure audit policies for Windows event logs | Microsoft Defender for Identity
3
-
description: This article describes how to configure audit policies for Windows event logs as part of deploying a Microsoft Defender for Identity sensor.
2
+
title: Configure advandced settings | Microsoft Defender for Identity
3
+
description: This article describes how to configure advanced settings of deploying a Microsoft Defender for Identity sensor.
4
4
ms.date: 11/05/2025
5
5
ms.topic: how-to
6
6
ms.reviewer: rlitinsky
@@ -10,7 +10,7 @@ ms.reviewer: rlitinsky
10
10
11
11
## Automatic Windows event auditing (Preview)
12
12
13
-
Defender for Identity detections rely on specific Windows event log entries to enhance detections and provide extra information about the users performing specific actions, such as NTLM sign-ins and security group modifications.
13
+
Defender for Identity uses specific Windows event log entries to enhance detections and provide extra information about the users performing specific actions, such as NTLM sign-ins and security group modifications.
14
14
This article describes how to configure the advanced audit policy settings to avoid gaps in the event logs and incomplete Defender for Identity coverage.
15
15
16
16
Defender for Identity generates health issues when it detects incorrect windows event auditing configurations. For more information, see [Microsoft Defender for Identity health alerts](../health-alerts.md).
@@ -31,7 +31,7 @@ When automatic windows event auditing is enabled, it:
31
31
- Configures local Windows audit policy using Windows Local Security Authority (LSA) audit policy APIs.
32
32
- Sends health alerts about the configuration state.
33
33
34
-
If you do not select automatic Windows auditing configuration, you must [manually configure Windows event auditing](configure-windows-event-collection.md) in the Defender portal or using PowerShell.
34
+
If you don't select automatic Windows auditing configuration, you must [manually configure Windows event auditing](configure-windows-event-collection.md) in the Defender portal or using PowerShell.
35
35
36
36
### Enable Automatic Windows event auditing
37
37
@@ -41,7 +41,7 @@ To turn on automatic windows auditing:
41
41
1. Turn on **Automatic Windows auditing configuration**.
42
42
43
43
## Disable Automatic Windows event auditing
44
-
When you turn off automatic windows auditing, Defender for Identity stops checking and applying the required audit settings on your domain controllers. Any configurations that were applied by automatic windows auditing remain unchanged.
44
+
When you turn off automatic windows auditing, Defender for Identity stops checking and applying the required audit settings on your domain controllers. Any configurations applied by automatic windows auditing remain unchanged.
45
45
46
46
To turn off automatic windows auditing:
47
47
1. In the [Microsoft Defender portal](https://security.microsoft.com), go to **Settings**, and then **Identities**.
0 commit comments