Configure an Active Directory Sensor Configure an Arctic Wolf GPO Advanced Audit Policy. Optional: Configure Active Directory Certificate Service (AD CS) auditing. Note: This step is required if you have the AD CS role configured on your server. Install NXLog on each DC. Install Active Directory Sensor on each DC. Install the Arctic Wolf Agent on each DC. Install Sysmon on each DC. Optional: NXLog for auditing ADFS. Optional: Active Directory decoy accounts.