| ES-PO-WIN-C-Server Audit Events | |
| Data collected on: 2-9-2025 11:46:04 | |
| Domain | emea.tpg.ads |
| Owner | EMEA\estevez.10-adm |
| Created | 22-12-2023 10:54:32 |
| Modified | 4-6-2024 10:42:24 |
| User Revisions | 0 (AD), 0 (SYSVOL) |
| Computer Revisions | 37 (AD), 37 (SYSVOL) |
| Unique ID | {a21b0a05-d06a-4f50-8ac6-5ab122cfeb68} |
| GPO Status | Enabled |
| Location | Enforced | Link Status | Path |
|---|---|---|---|
| Servers | No | Enabled | emea.tpg.ads/ES/Systems/Servers |
| Name |
|---|
| EMEA\ES-L-SEC-Server Audit Events |
| Name | Allowed Permissions | Inherited |
|---|---|---|
| EMEA\Domain Admins | Edit settings, delete, modify security | No |
| EMEA\ES-L-SEC-Delegation Full Access | Edit settings, delete, modify security | No |
| EMEA\ES-L-SEC-Server Audit Events | Read (from Security Filtering) | No |
| NT AUTHORITY\Authenticated Users | Read | No |
| NT AUTHORITY\ENTERPRISE DOMAIN CONTROLLERS | Read | No |
| NT AUTHORITY\SYSTEM | Edit settings, delete, modify security | No |
| ROOT\Enterprise Admins | Edit settings, delete, modify security | No |
| Policy | Setting |
|---|---|
| Audit account logon events | Success, Failure |
| Audit account management | Success, Failure |
| Audit directory service access | Success, Failure |
| Audit logon events | Success, Failure |
| Audit object access | Success, Failure |
| Audit policy change | Success, Failure |
| Audit privilege use | Success, Failure |
| Audit process tracking | Success, Failure |
| Audit system events | Success, Failure |
| Policy | Setting |
|---|---|
| Audit: Force audit policy subcategory settings (Windows Vista or later) to override audit policy category settings | Enabled |
| Policy | Setting |
|---|---|
| Prevent local guests group from accessing application log | Enabled |
| Prevent local guests group from accessing security log | Enabled |
| Prevent local guests group from accessing system log | Enabled |
| Retain application log | 90 days |
| Retain security log | 90 days |
| Retain system log | 90 days |
| Retention method for application log | By days |
| Retention method for security log | By days |
| Retention method for system log | By days |
| Policy | Setting |
|---|---|
| Audit Credential Validation | Success, Failure |
| Policy | Setting |
|---|---|
| Audit Application Group Management | Success, Failure |
| Audit Computer Account Management | Success, Failure |
| Audit Distribution Group Management | Success, Failure |
| Audit Other Account Management Events | Success, Failure |
| Audit Security Group Management | Success, Failure |
| Audit User Account Management | Success, Failure |
| Policy | Setting |
|---|---|
| Audit Process Creation | Success, Failure |
| Audit Process Termination | Success |
| Policy | Setting |
|---|---|
| Audit Detailed Directory Service Replication | Success, Failure |
| Audit Directory Service Access | Success, Failure |
| Audit Directory Service Changes | Success, Failure |
| Audit Directory Service Replication | Success, Failure |
| Policy | Setting |
|---|---|
| Audit Account Lockout | Success |
| Audit Logoff | Success, Failure |
| Audit Logon | Success, Failure |
| Audit Other Logon/Logoff Events | Success |
| Audit Special Logon | Success, Failure |
| Policy | Setting |
|---|---|
| Audit File System | Success |
| Audit Handle Manipulation | Failure |
| Policy | Setting |
|---|---|
| Audit Audit Policy Change | Success, Failure |
| Audit Authentication Policy Change | Success, Failure |
| Audit Authorization Policy Change | Success, Failure |
| Audit Filtering Platform Policy Change | Success, Failure |
| Audit MPSSVC Rule-Level Policy Change | Success, Failure |
| Audit Other Policy Change Events | Success, Failure |
| Policy | Setting |
|---|---|
| Audit Other System Events | Success, Failure |
| Audit Security State Change | Success, Failure |
| Audit Security System Extension | Success |
| Audit System Integrity | Success, Failure |