Advanced Audit Policy Konfigürasyonu

Active Directory Advanced Audit Policy için önerilen konfigürasyon aşağıdaki gibidir.

Audit Policy PC Server DC 
Audit Policy Category or SubcategoryWindows Default Baseline Recommendation Stronger Recommendation 
 SuccessFailureSuccessFailureSuccessFailure
Account Logon      
Audit Credential ValidationNONOYESYES YES
Audit Kerberos Authentication Service    YESYES
Audit Kerberos Service Ticket Operations    YESYES
Audit Other Account Logon Events    YESYES
Account Management      
Audit Application Group Management      
Audit Computer Account Management  YESDCYESYES
Audit Distribution Group Management      
Audit Other Account Management Events  YESYESYESYES
Audit Security Group Management  YESYESYESYES
Audit User Account ManagementYESNOYESYESYESYES
Detailed Tracking      
Audit DPAPI Activity    YESYES
Audit Process Creation  YESNOYESYES
Audit Process Termination      
Audit RPC Events      
DS Access      
Audit Detailed Directory Service Replication      
Audit Directory Service Access  DCDCDCDC
Audit Directory Service Changes  DCDCDCDC
Audit Directory Service Replication      
Logon and Logoff      
Audit Account LockoutYESNO  YESNO
Audit User/Device Claims      
Audit IPsec Extended Mode      
Audit IPsec Main Mode    IFIF
Audit IPsec Quick Mode      
Audit LogoffYESNOYESNOYESNO
Audit LogonYESNOYESYESYESYES
Audit Network Policy ServerYESYES    
Audit Other Logon/Logoff Events    YESYES
Audit Special LogonYESNOYESNOYESYES
Object Access      
Audit Application Generated      
Audit Certification Services      
Audit Detailed File Share      
Audit File Share      
Audit File System      
Audit Filtering Platform Connection      
Audit Filtering Platform Packet Drop      
Audit Handle Manipulation      
Audit Kernel Object      
Audit Other Object Access Events      
Audit Registry      
Audit Removable Storage      
Audit SAM      
Audit Central Access Policy Staging      
Policy Change      
Audit Audit Policy ChangeYESNOYESYESYESYES
Audit Authentication Policy ChangeYESNOYESNOYESYES
Audit Authorization Policy Change      
Audit Filtering Platform Policy Change      
Audit MPSSVC Rule-Level Policy Change    YES 
Audit Other Policy Change Events      
Privilege Use      
Audit Non-Sensitive Privilege Use      
Audit Other Privilege Use Events      
Audit Sensitive Privilege Use  YESYESYESYES
System      
Audit IPsec Driver  YESYESYESYES
Audit Other System EventsYESYES    
Audit Security State ChangeYESNOYESYESYESYES
Audit Security System Extension  YESYESYESYES
Audit System IntegrityYESYESYESYESYESYES
Global Object Access Auditing      
Audit IPsec Driver      
Audit Other System Events      
Audit Security State Change      
Audit Security System Extension      
Audit System Integrity