Post

Active Directory Advanced Audit Policy GPO Configuration

Active Directory Advanced Audit Policy GPO Configuration

Active Directory Advanced Audit Policy, Windows Server işletim sisteminde Active Directory (AD) hizmeti için gelişmiş denetim politikalarını yönetmeyi sağlayan bir özelliktir. Geleneksel denetim politikalarından farklı olarak, gelişmiş denetim politikaları, daha kapsamlı ve esnek denetim olanakları sunar. Bu özellik, özellikle büyük kuruluşlar ve güvenlik gereksinimleri yüksek ortamlar için önemli bir araçtır.

Gelişmiş denetim politikaları, Active Directory'deki nesneler ve kayıtlar üzerindeki değişiklikleri ayrıntılı bir şekilde izlemeye ve denetlemeye olanak tanır. Yöneticiler, belirli olaylarla ilgili ayrıntılı logları etkinleştirerek, izlemek ve olayları raporlamak için daha fazla seçeneğe sahip olurlar.

Gelişmiş denetim politikaları, Olay kimlikleri (event IDs) ile ilişkilendirilir ve olay günlüklerine yazılan belirli eylemleri denetler. Örneğin, kullanıcı hesabı oluşturma, hesap silme, şifre değiştirme veya grup üyeliği değiştirme gibi olayları izlemek ve raporlamak için bu politikaları kullanabilirsiniz.

Policy Location:

"Computer Configuration -> Policies -> Windows Settings -> Security Settings -> Advanced Audit Policy Configuration"

Gelişmiş Denetim Politikası Yapılandırması için önerilen ayarlar şu şekildedir.

Account Logon

NamePolicy SettingDescription
Audit Credential ValidationFailureThis policy setting allows you to audit events generated by validation tests on user account logon credentials.
Audit Kerberos Authentication ServicesFailureThis policy setting allows you to audit events generated by Kerberos authentication ticket-granting ticket (TGT) requests.
Audit Kerberos Service Ticket OperationsSuccess and FailureThis policy setting allows you to audit events generated by Kerberos authentication ticket-granting ticket (TGT) requests submitted for user accounts.

Account Management

NamePolicy SettingDescription
Audit Computer Account ManagementSuccessThis policy setting allows you to audit events generated by changes to computer accounts such as when a computer account is created, changed, or deleted.
Audit Other Account Management EventsSuccessThis policy setting allows you to audit events generated by other user account changes that are not covered in this category, such as the following:
Audit Security Group ManagementSuccessThis policy setting allows you to audit events generated by changes to security groups such as the following:
Audit User Account ManagementSuccess and FailureThis policy setting allows you to audit changes to user accounts

Detailed Tracking

NamePolicy SettingDescription
Audit PNP ActivitySuccessThis policy setting allows you to audit when plug and play detects an external device.
Audit Process CreationSuccessThis policy setting allows you to audit events generated when a process is created or starts. The name of the application or user that created the process is also audited.

DS Access

NamePolicy SettingDescription
Audit Directory Service AccessFailureThis policy setting allows you to audit events generated when an Active Directory Domain Services (AD DS) object is accessed.
Audit Directory Service ChangesSuccessThis policy setting allows you to audit events generated by changes to objects in Active Directory Domain Services (AD DS). Events are logged when an object is created, deleted, modified, moved, or undeleted.

Logon/Logoff

NamePolicy SettingDescription
Audit Account LockoutFailureThis policy setting allows you to audit events generated by a failed attempt to log on to an account that is locked out.
Audit Group MembershipSuccessThis policy allows you to audit the group memberhsip information in the user’s logon token
Audit LogonSuccess and FailureThis policy setting allows you to audit events generated by user account logon attempts on the computer.
Audit Other Logon/Logoff EventsSuccess and FailureThis policy setting allows you to audit other logon/logoff-related events that are not covered in the “Logon/Logoff”.
Audit Special LogonSuccessThis policy setting allows you to audit events generated by special logons such as those with administrator equivalent privileges.

Object Access

NamePolicy SettingDescription
Audit Detailed File ShareFailureThis policy setting allows you to audit attempts to access files and folders on a shared folder.
Audit File ShareSuccess and FailureThis policy setting allows you to audit attempts to access a shared folder.
Audit Other Object Access EventsSuccess and FailureThis policy setting allows you to audit events generated by the management of task scheduler jobs or COM+ objects.
Audit Removable StorageSuccess and FailureThis policy setting allows you to audit user attempts to access file system objects on a removable storage device. A security audit event is generated only for all objects for all types of access requested.

Policy Change

NamePolicy SettingDescription
Audit Audit Policy ChangeSuccessThis policy setting allows you to audit changes in the security audit policy settings.
Audit Authentication Policy ChangeSuccessThis policy setting allows you to audit events generated by changes to the authentication policy
Audit MPSSVC Rule-Level Policy ChangeSuccess and FailureThis policy setting allows you to audit events generated by changes in policy rules used by the Microsoft Protection Service (MPSSVC)
Audit Other Policy Change EventsFailureThis policy setting allows you to audit events generated by other security policy changes that are not audited in the policy change category

Privilege Use

NamePolicy SettingDescription
Audit Sensitive Privilege UseSuccess and FailureThis policy setting allows you to audit events generated when sensitive privileges (user rights) are used.

System

NamePolicy SettingDescription
Audit Other System EventsSuccess and FailureThis policy setting allows you to audit systems events such as the startup and shutdown of the Windows firewall.
Audit Security State ChangeSuccessThis policy setting allows you to audit systems events such as the startup and shutdown of the Windows firewall.
Audit Security System ExtensionSuccessThis policy setting allows you to audit events related to security system extensions or services
Audit System IntegritySuccess and FailureThis policy setting allows you to audit events that violate the integrity of the security subsystem

Global Object Access Auditing

NamePolicy SettingDescription
File System
Registery

Bu Windows denetim politikası ayarlarını etkinleştirdiğinizde, alan denetleyicilerinizde Active Directory Günlükleri oluşturulur. Bu günlükler, Windows olay görüntüleyici kullanılarak görüntülenebilir ancak bunları analiz etmek için 3. Parti vb. bir denetim aracı kullanmanızı öneririm.

Saygılarımla. – Best regards.

This post is licensed under CC BY 4.0 by the author.