diff --git a/ATPDocs/deploy/configure-windows-event-collection.md b/ATPDocs/deploy/configure-windows-event-collection.md index 510b952616..112b88d534 100644 --- a/ATPDocs/deploy/configure-windows-event-collection.md +++ b/ATPDocs/deploy/configure-windows-event-collection.md @@ -235,15 +235,16 @@ To configure domain object auditing: Now, all relevant changes to directory services appear as 4662 events when they're triggered. -1. Repeat the steps in this procedure, but for **Applies to**, select the following object types: +1. Repeat the steps in this procedure, but for **Applies to**, select the following object types 1 - **Descendant Group Objects** - **Descendant Computer Objects** - **Descendant msDS-GroupManagedServiceAccount Objects** - **Descendant msDS-ManagedServiceAccount Objects** - - **Descendant msDS-DelegatedManagedServiceAccount Objects** + - **Descendant msDS-DelegatedManagedServiceAccount Objects** 2 > [!NOTE] -> Assigning the auditing permissions on **All descendant objects** would also work, but you need only the object types detailed in the last step. +> 1. Assigning the auditing permissions on **All descendant objects** would also work, but you need only the object types detailed in the last step. +> 2. The **msDS-DelegatedManagedServiceAccount** class is relevant only for domains running at least one Windows Server 2025 domain controller. ## Configure auditing on AD FS