Audit directory service access

Information

Audit directory service access

This security setting determines whether the OS audits user attempts to access Active Directory objects. Audit is only generated for objects that have system access control lists (SACL) specified, and only if the type of access requested (such as Write, Read, or Modify) and the account making the request match the settings in the SACL.

The administrator can specify whether to audit only successes, only failures, both successes and failures, or to not audit these events at all (i.e. neither successes nor failures).

If Success auditing is enabled, an audit entry is generated each time any account successfully accesses a Directory object that has a matching SACL specified.

If Failure auditing is enabled, an audit entry is generated each time any user unsuccessfully attempts to access a Directory object that has a matching SACL specified.

Default:

Success on domain controllers.
Undefined for a member computer.

Solution

Policy Path: Computer Configuration\Windows Settings\Advanced Audit Policy Configuration\Audit Policies\DS Access
Policy Setting Name: Audit directory service access

See Also

https://www.microsoft.com/en-us/download/details.aspx?id=55319

Item Details

Category: AUDIT AND ACCOUNTABILITY

References: 800-53|AU-12c.

Plugin: Windows

Control ID: 8d1827dbc563de1dffb551d56fc9db2d28d4fb2da033d4d5869d20c456d8b7ac