Microsoft Windows Server 2019 - Advanced auditing

JoeS-0122 41 Reputation points
2024-09-12T14:40:20.3966667+00:00

Any chance a windows expert could assist with with advanced auditting group policy? it is turned on and shows the correct settings when i run an auditpol but when i do an rsop check, Advanced Auditing is missing under this check. When i perform an MDI readiness report is shows advanced auditing is turned off. We have a seperate policy created with these settings(we did not use the default domain policy as per best practice). Also we a policy does have the Audit: Force audit policy subcategory settings (Windows Vista or later) to override audit policy category settings. turned on. Any assistance would be appreciated

Windows Server 2019
Windows Server 2019
A Microsoft server operating system that supports enterprise-level management updated to data storage.
3,743 questions
Microsoft Defender for Identity
Microsoft Defender for Identity
A Microsoft service that helps protect enterprise hybrid environments from multiple types of advanced, targeted cyberattacks and insider threats.
201 questions
0 comments No comments
{count} votes

2 answers

Sort by: Most helpful
  1. Wesley Li 8,775 Reputation points
    2024-09-12T14:59:08.3733333+00:00

    Hello

    It sounds like you're experiencing some issues with the advanced auditing group policy settings. Here are a few steps and considerations that might help resolve the issue:

     

    Verify Policy Application: Ensure that the separate policy you created is correctly linked to the appropriate Organizational Unit (OU) and that it has higher precedence over other conflicting policies. You can use the gpresult /H c:\gpresults.html command to generate a report and verify which policies are being applied.

     

    Audit: Force Audit Policy Subcategory Settings: You mentioned that this setting is turned on. This is crucial as it ensures that the advanced audit policy settings override the basic audit policy settings. Double-check that this setting is correctly configured in the policy.

     

    Check for Conflicting Policies: Sometimes, local policies or other group policies might conflict with your advanced audit policy settings. Running auditpol /get /category:* can help you see the current audit policy settings and identify any discrepancies.

     

    MDI Readiness Report: If the MDI readiness report shows that advanced auditing is turned off, it might be due to a delay in policy application or a conflict with another policy. Ensure that the policy is correctly applied and that there are no errors in the event logs related to group policy application.

     

    Policy Refresh: Force a group policy update on the affected machines using the gpupdate /force command. This ensures that the latest policy settings are applied.

     

    Consult with Experts: Given the complexity of group policies and advanced auditing, it might be helpful to consult with a Windows Online Support Expert.

    Contact Us - Microsoft Support


  2. JoeS-0122 41 Reputation points
    2024-09-12T15:43:50.31+00:00

    .

    .

    .

    .

    .

    .

    .

    .

    .

    0 comments No comments

Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.