Configure an Arctic Wolf GPO Advanced Audit Policy
To capture security-relevant events on Windows devices and Active Directory (AD) domain controllers, you must configure audit policies for each domain to generate events in the Windows Event Log. These policy settings generate events that give your Concierge Security® Team (CST) visibility into your Windows environment.
When you configure the Arctic Wolf® Group Policy Object (GPO) Advanced Audit Policy using the Group Policy Management Console (GPMC), advanced security audit policy settings apply to all domain controllers, servers, and workstations in your domain. If you have any questions or concerns about these audit policy settings and their alignment with your company practices, contact your CST.
These resources are required:
- Windows Server 2012 R2 and newer
These actions are required:
- Make sure you have an audit policy configured for each domain to generate events in the Windows Event Log. This enables Arctic Wolf to monitor security and operational events in your environment.
Open or create an Arctic Wolf GPO Advanced Audit Policy
Configure Advanced Audit Policy settings
Enforce the Arctic Wolf GPO Advanced Audit Policy
Enabling this option ensures that the policy settings defined in a higher-level GPO take precedence, preventing any lower-level GPOs within AD from overriding them. For more information about GPO priority, see Group Policy processing.
Set the precedence of an Advanced Audit Policy
The Arctic Wolf GPO requires precedence over other GPOs.
Update the domain controller Group Policy
Optional: Configure AD CS monitoring
If you are using the AD Certificate Service role configured on your server, this step is required.
certutil -setreg CA\AuditFilter 127
Restart-Service certsvc