+ All Categories
Home > Documents > Module 12: Auditing Active Directory Domain Services Changes.

Module 12: Auditing Active Directory Domain Services Changes.

Date post: 30-Dec-2015
Category:
Upload: derek-poole
View: 219 times
Download: 2 times
Share this document with a friend
Popular Tags:
13
Module 12: Auditing Active Directory Domain Services Changes
Transcript
Page 1: Module 12: Auditing Active Directory Domain Services Changes.

Module 12:Auditing Active Directory Domain Services Changes

Page 2: Module 12: Auditing Active Directory Domain Services Changes.

Overview

Identify new features in AD DS auditing

Implement AD DS auditing

Page 3: Module 12: Auditing Active Directory Domain Services Changes.

Lesson 1: What’s New with AD DS Auditing

Identify the four new auditing subcategories

List the new capabilities enabled with the new auditing subcategories

Page 4: Module 12: Auditing Active Directory Domain Services Changes.

Auditing Overview

Audit directory service access

generic object operation took place.

566A

DescriptionDirectory service access events

Page 5: Module 12: Auditing Active Directory Domain Services Changes.

Auditing with Windows Server 2008

Audit Directory Service Access

Directory Service Access

Directory Service Changes

Directory Service Replication

Detailed Directory Service Replication

Page 6: Module 12: Auditing Active Directory Domain Services Changes.

Lesson 2: Implementing AD DS Change Auditing

Describe the global audit policy

Describe the System Access Control List

Describe how the schema can be used to filter events that are audited

List the event ID for directory service access events

Describe attribute syntaxes

Page 7: Module 12: Auditing Active Directory Domain Services Changes.

Global Audit Policy

generic object operation took place.566A

DescriptionDirectory service access events

generic object operation took place.4662

DescriptionDirectory service access events

Windows Server 2000 and Windows Server 2003

Windows Server 2008

Page 8: Module 12: Auditing Active Directory Domain Services Changes.

System Access Control List

SACL

Page 9: Module 12: Auditing Active Directory Domain Services Changes.

Schema

Schema

Event Type 1

Event Type 2

Event Type 3

Event Type 4

Event Type 5

Audited

Page 10: Module 12: Auditing Active Directory Domain Services Changes.

New AD DS Auditing Events

Modify 5136

Create 5137

Undelete 5138

Move 5139

Page 11: Module 12: Auditing Active Directory Domain Services Changes.

Example 1

Page 12: Module 12: Auditing Active Directory Domain Services Changes.

Example 2

Page 13: Module 12: Auditing Active Directory Domain Services Changes.

Attribute Syntaxes

Registry setting information is as follows:

Location: HKLM\System\CurrentControlSet\Services\NTDS\Setting name: MaximumStringBytesToAudit

Type: REG_DWORD

Values

Default registry value: 1000

Minimum registry value: 0

Maximum registry value 64000


Recommended