Defender for Identity - Directory Services Advanced Auditing is not enabled

OwlTecAB 60 Reputation points
2023-09-27T20:12:12.2233333+00:00

Hi Everyone,

We have followed the following guide from Microsoft in regards to enabling "advanced auditing" for Defender for Identity:

Screenshot 2023-09-27 at 1.52.25 PM

Any ideas?

I am certain have configured our GPO properly (but you never know):

Screenshot 2023-09-27 at 1.34.51 PM

Screenshot 2023-09-27 at 1.35.28 PM

Screenshot 2023-09-27 at 1.35.41 PM

Screenshot 2023-09-27 at 1.35.54 PM

Screenshot 2023-09-27 at 1.36.44 PM

Screenshot 2023-09-27 at 1.46.40 PM

Here are the results of running "auditpol /get /category:*" on one of the servers that this policy has been applied to:

Screenshot 2023-09-27 at 2.13.04 PM

Screenshot 2023-09-27 at 2.13.14 PM

As always, thanks for the help!

Windows for business | Windows Client for IT Pros | Directory services | Active Directory
Microsoft Security | Microsoft Defender | Microsoft Defender for Identity
Windows for business | Windows Client for IT Pros | User experience | Other
{count} vote

2 answers

Sort by: Most helpful
  1. Limitless Technology 44,771 Reputation points
    2023-09-28T11:22:10.5666667+00:00

    Hello

    Thank you for your question and reaching out.

    Please check below steps and make sure you have checked all relevant event log entries to be enabled for GPO.

    https://techcommunity.microsoft.com/t5/itops-talk-blog/step-by-step-enabling-advanced-security-audit-policy-via/ba-p/282452

    --If the reply is helpful, please Upvote and Accept as answer--


  2. OwlTecAB 60 Reputation points
    2023-09-28T13:19:39.1166667+00:00

    Thanks for the link, however I have just confirmed that the relevant logs are on found on my DCs (that was applied via my GPO):Screenshot 2023-09-28 at 7.17.26 AM

    Screenshot 2023-09-28 at 7.14.05 AM

    Screenshot 2023-09-28 at 7.15.28 AM

    What I just did, was push the policies again from the "Default Domain Controllers Policy" GPO instead of the separate one I had created to see if that fixes the issue.

    Edit: Pushing the polices to "Default Domain Controllers Policy" GPO, instead of a separate GPO, is what fixed it. I guess this is a super common bug with enabling Advanced Audit that has been resolved.


Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.