WinSecWiki
Windows Security Settings
Articles
WinSecWiki
»
Windows Security Settings
»
Local Policies
»
Audit Policy
»
Audit directory service access
»
Directory Service Access
Directory Service Access
Directory Service Access
This category only generates events on domain controllers and tracks access attempts on Active Directory objects (which have object level auditing enabled) but not changes to those objects. See
Directory Service Changes
. Typically I recommend disabling this category and using
Directory Service Changes
to track actual changes. To configure this you must use
auditpol.
Coverage on events generated by this category are currently in the
Security Log Encyclopedia
:
Event ID
Title
4661
A handle to an object was requested
4662
An operation was performed on an object
5139
A directory service object was moved.
Add Your Comments
Name:
*
Email Address:
Web Address:
Verification Code:
*
Details
Article not rated yet.
Article has been viewed 1,657 times.
Options
Bookmark Article
Social Bookmarks
Comments RSS
Upcoming Webinars
Web Protection: The Missing Link in the Endpoint Security Chain?
File Integrity Monitoring with the Windows Security Log
Anatomy of an Attack: What Happened at RSA and What Can We Learn From It?
Implementing Virtual Security Cameras to Protect Privileged Access and Enforce Accountability
Additional Resources
Security Log Quick Reference Chart
Security Log Resource Kit
Learn about the SharePoint Audit Log
Patch Tuesday Analysis
Home
>
Windows
>
WinSecWiki
User name:
Password:
/
Forgot?
Register
Home