Configure an Arctic Wolf GPO Advanced Audit Policy

To capture security-relevant events on Windows devices and Active Directory (AD) domain controllers, you must configure audit policies for each domain to generate events in the Windows Event Log. These policy settings generate events that give your Concierge Security® Team (CST) visibility into your Windows environment.

When you configure the Arctic Wolf® Group Policy Object (GPO) Advanced Audit Policy using the Group Policy Management Console (GPMC), advanced security audit policy settings apply to all domain controllers, servers, and workstations in your domain. If you have any questions or concerns about these audit policy settings and their alignment with your company practices, contact your CST.

These resources are required:

  • Windows Server 2012 R2 and newer

These actions are required:

  • Make sure you have an audit policy configured for each domain to generate events in the Windows Event Log. This enables Arctic Wolf to monitor security and operational events in your environment.

Open or create an Arctic Wolf GPO Advanced Audit Policy

  1. Click Start, and then open the GPMC.
  2. In the navigation menu, click Forest: <DomainName>, where DomainName is the name of your domain, and then click the Domains folder.
  3. Right-click the domain name. If you:
    • Already have an AD advanced audit policy GPO — Select Link an Existing GPO, and then click Edit.
    • Do not have an existing AD advanced audit policy GPO — Create a new GPO:
      1. Select Create a GPO in this domain, and Link it here.
      2. In the New GPO dialog box, enter a name for the new GPO.
      3. Verify that the Source Starter GPO menu says (none).
      4. Click OK.
      5. Right-click the new GPO, and then click Enforced to enable it.

        The GPO is enabled. A lock appears on the GPO icon in the navigation menu.

      6. Right-click the new GPO, and then select Edit.

Configure Advanced Audit Policy settings

  1. Set the Force audit policy subcategory settings (Windows Vista or later) to override audit policy category settings policy to Enabled:
    1. In the Group Policy Management Editor navigation menu, click Computer Configuration > Policies > Windows Settings > Security Settings > Local Policies > Security Options.
    2. Right-click Audit: Force audit policy subcategory settings (Windows Vista or later) to override audit policy category settings, and then select Properties.
    3. Click the Security Policy Setting tab.
    4. Select the Define this policy setting checkbox, and then select Enabled.
    5. Click OK.

      See the Microsoft documentation for this security option for more information.

  2. In the Group Policy Management Editor, in the navigation menu, click Computer Configuration > Policies > Windows Settings > Security Settings > Advanced Audit Policy Configuration > Audit Policies.
    Tip:

    Resize the window and enable tree view to completely view the policy tree.

    Audit Policy location in the Group Policy Management Editor

  3. Edit the audit policy settings:
    1. In the Audit Policies section, select the category. For example, Account Logon.
    2. Double-click the corresponding subcategory. For example, Audit Credential Validation.
    3. Edit the policy setting as indicated in the table.
    4. Verify that each setting has these checkboxes selected:
      • Configure the following audit events
      • Success or Failure, according to the Audit Events listed in the table.

    This table lists the policy setting checkboxes to select:

    Category

    Subcategory

    Audit event settings

    Notes

    Account Logon

    Audit Credential Validation

    Success and Failure

    Account Logon

    Audit Kerberos Authentication Service

    Success and Failure

    Account Logon

    Audit Kerberos Service Ticket Operations

    Success and Failure

    Account Logon

    Audit Other Account Logon Events

    Success and Failure

    Account Management

    Audit Computer Account Management

    Success and Failure

    Account Management

    Audit Security Group Management

    Success and Failure

    Account Management

    Audit User Account Management

    Success and Failure

    Detailed Tracking

    Audit DPAPI Activity

    Success

    Detailed Tracking

    Audit Process Creation

    Success

    Detailed Tracking

    Audit Process Termination

    Success

    See Audit Process Termination.

    Detailed Tracking

    Audit Token Right Adjusted

    Success

    See Audit Token Right Adjusted.

    DS Access

    Audit Directory Service Access

    Success

    DS Access

    Audit Directory Service Changes

    Success

    Logon/Logoff

    Audit Account Lockout

    Success and Failure

    Logon/Logoff

    Audit Logoff

    Success and Failure

    Logon/Logoff

    Audit Logon

    Success and Failure

    Logon/Logoff

    Audit Network Policy Server

    Success and Failure

    Only applies if using NPS on this AD domain.

    Logon/Logoff

    Audit Other Logon/Logoff Events

    Success and Failure

    Logon/Logoff

    Audit Special Logon

    Success and Failure

    Object Access

    Audit Detailed File Share

    Success and Failure

    Object Access

    Audit Certification Services

    Success and Failure

    Only applies if using ADCS on this AD domain. For further instruction, see Optional: Configure AD CS monitoring.

    Policy Change

    Audit Audit Policy Change

    Success and Failure

    Policy Change

    Audit Authentication Policy Change

    Success and Failure

    Policy Change

    Audit Authorization Policy Change

    Success and Failure

    Policy Change

    Audit MPSSVC Rule-Level Policy Change

    Success

    Privilege Use

    Audit Sensitive Privilege Use

    Success and Failure

    System

    Audit IPsec Driver

    Success

    Only applies if you use IPsec on this AD domain.

    System

    Audit Other System Events

    Success and Failure

    System

    Audit Security State Change

    Success and Failure

    System

    Audit Security System Extension

    Success and Failure

    System

    Audit System Integrity

    Success and Failure

  4. In the same Group Policy, enable these command-line policies:
    Note:

    These configuration options do not appear unless the functional level of the domain is Windows Server 2012 R2 or higher. For more information, see Active Directory Domain Services Functional Levels in Windows Server.

    • Click Computer Configuration > Policies > Administrative Templates > System > Audit Process Creation, and then set Include command line in process creation events to Enabled.

      Audit Policy location in the Group Policy Management Editor

    • Click Computer Configuration > Policies > Administrative Templates > Windows Components > Windows PowerShell, and then set Turn on PowerShell Script Block Logging to Enabled.

      Audit Policy location in the Group Policy Management Editor

  5. Close the Group Policy Management Editor window after completing all audit and command-line policy changes.
  6. In the navigation menu, click AWN Audit Policy.
  7. Click the Settings tab.
  8. Compare the policy configuration settings to the audit policy settings that you edited earlier.
    Note:

    Even if the settings here are correct, they might not have been applied yet.

Enforce the Arctic Wolf GPO Advanced Audit Policy

Enabling this option ensures that the policy settings defined in a higher-level GPO take precedence, preventing any lower-level GPOs within AD from overriding them. For more information about GPO priority, see Group Policy processing.

Right-click your Arctic Wolf GPO Audit Policy, and then select Enforced.
A lock appears on the GPO icon indicating that it is enforced.

Set the precedence of an Advanced Audit Policy

The Arctic Wolf GPO requires precedence over other GPOs.

  1. In the navigation menu, click Forest: DomainName, where DomainName is the name of your domain, and then click the Domains folder.
  2. Click the Linked Group Policy Objects tab.
  3. In the GPO column, locate and click the Arctic Wolf GPO, and then use the up and down arrows to move the GPO to the top of the list.
  4. Verify that the Arctic Wolf GPO has these settings:
    • Link Order1.
    • EnforcedYes.
  5. Close the Group Policy Management window.

Update the domain controller Group Policy

  1. Click Start > Windows PowerShell or Command Prompt.
  2. Run this command:
    SHELL
    gpupdate /force
    Note:

    If you are prompted to sign off or restart after the user and computer policy updates complete, press N, and then press Enter.

  3. Close Windows PowerShell or the Command Prompt.

    The audit settings are now successfully applied with Group Policy.

Optional: Configure AD CS monitoring

If you are using the AD Certificate Service role configured on your server, this step is required.

For more information, see Configure Active Directory Certificate Service (AD CS) auditing.
In PowerShell, run this command:
POWERSHELL
certutil -setreg CA\AuditFilter 127 
Restart-Service certsvc