Audit Policies
Types of Audit Policies
Logon/Logoff Events: Tracks when users log on and off the system.
Object Access: Monitors when files, folders, and other objects are accessed.
Account Logon: Monitors when users authenticate against a domain controller (for domain-based systems).
Directory Service Access: Audits access to Active Directory objects.
Account Management: Tracks changes to user accounts, group memberships, and permissions.
Logon/Logoff Events: Captures successful and failed login attempts.
Privilege Use: Tracks the use of sensitive system privileges, like changing system time or backing up files.
System Events: Audits system-level events such as system shutdowns, restarts, or system service changes.
Configuring Audit Policies through Group Policy
1. Open the Group Policy Editor
Press
Win + R
, typegpedit.msc
, and press Enter.
2. Navigate to the Audit Policy Settings
For local policies, go to:
3. Configure Audit Policies
Under Advanced Audit Policy Configuration, you'll see several categories of policies, such as:
Account Logon
Logon/Logoff
Object Access
Account Management
Directory Service Access
Privilege Use
System Events
This policies configurations may vary depending to organisation & organisations so please check the policy path and enable the policy settings according to compliance requirement of the organisation
Last updated