You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Copy file name to clipboardExpand all lines: ATPDocs/deploy/configure-windows-event-collection.md
+6-6Lines changed: 6 additions & 6 deletions
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -58,7 +58,7 @@ Use the following procedures to configure auditing on the domain controllers tha
58
58
59
59
This procedure describes how to modify your domain controller's Advanced Audit Policy settings as needed for Defender for Identity via the UI.
60
60
61
-
**Related health issue:**[Directory Services Advanced Auditing is not enabled as required](../health-alerts.md#directory-services-advanced-auditing-isn't-enabled-as-required)
61
+
**Related health issue:**[Directory Services Advanced Auditing is not enabled as required](../health-alerts.md#directory-services-advanced-auditing-is-not-enabled-as-required)
62
62
63
63
To configure your Advanced Audit Policy settings:
64
64
@@ -113,7 +113,7 @@ For more information, see the [auditpol reference documentation](/windows-server
113
113
114
114
The following actions describe how to modify your domain controller's Advanced Audit Policy settings as needed for Defender for Identity by using PowerShell.
115
115
116
-
**Related health issue:**[Directory Services Advanced Auditing is not enabled as required](../health-alerts.md#directory-services-advanced-auditing-isn't-enabled-as-required)
116
+
**Related health issue:**[Directory Services Advanced Auditing is not enabled as required](../health-alerts.md#directory-services-advanced-auditing-is-not-enabled-as-required)
117
117
118
118
To configure your settings, run:
119
119
@@ -166,7 +166,7 @@ This section describes the extra configuration steps that you need for auditing
166
166
> - Domain group policies to collect Windows event 8004 should be applied *only* to domain controllers.
167
167
> - When a Defender for Identity sensor parses Windows event 8004, Defender for Identity NTLM authentication activities are enriched with the server-accessed data.
168
168
169
-
**Related health issue:**[NTLM Auditing is not enabled](../health-alerts.md#ntlm-auditing-isn't-enabled)
169
+
**Related health issue:**[NTLM Auditing is not enabled](../health-alerts.md#ntlm-auditing-is-not-enabled)
170
170
171
171
To configure NTLM auditing:
172
172
@@ -191,7 +191,7 @@ To collect events for object changes, such as for event 4662, you must also conf
191
191
> [!IMPORTANT]
192
192
> Review and audit your policies (via the [UI](#configure-advanced-audit-policy-settings-from-the-ui) or [PowerShell](#configure-advanced-audit-policy-settings-by-using-powershell)) before you enable event collection, to ensure that the domain controllers are properly configured to record the necessary events. If this auditing is configured properly, it should have a minimal effect on server performance.
193
193
194
-
**Related health issue:**[Directory Services Object Auditing is not enabled as required](../health-alerts.md#directory-services-object-auditing-isn't-enabled-as-required)
194
+
**Related health issue:**[Directory Services Object Auditing is not enabled as required](../health-alerts.md#directory-services-object-auditing-is-not-enabled-as-required)
195
195
196
196
To configure domain object auditing:
197
197
@@ -245,7 +245,7 @@ To configure domain object auditing:
245
245
246
246
## Configure auditing on AD FS
247
247
248
-
**Related health issue:**[Auditing on the AD FS container is not enabled as required](../health-alerts.md#auditing-on-the-adfs-container-isn't-enabled-as-required)
248
+
**Related health issue:**[Auditing on the AD FS container is not enabled as required](../health-alerts.md#auditing-on-the-adfs-container-is-not-enabled-as-required)
249
249
250
250
To configure auditing on Active Directory Federation Services (AD FS):
251
251
@@ -330,7 +330,7 @@ To configure auditing on Microsoft Entra Connect servers:
330
330
>[!NOTE]
331
331
> The configuration container audit is required only for environments that currently have or previously had Microsoft Exchange, as these environments have an Exchange container located within the domain's Configuration section.
332
332
333
-
**Related health issue:** [Auditing on the Configuration container is not enabled as required](../health-alerts.md#auditing-on-the-configuration-container-isn't-enabled-as-required)
333
+
**Related health issue:** [Auditing on the Configuration container is not enabled as required](../health-alerts.md#auditing-on-the-configuration-container-is-not-enabled-as-required)
334
334
335
335
1. Open the ADSI Edit tool. Select **Start** > **Run**, enter `ADSIEdit.msc`, and then select **OK**.
0 commit comments