WinSecWiki > Security Settings > Advanced Audit Policies > DS Access > Directory Service Access
Audit Directory Service Access
This category only generates events on domain controllers and tracks access attempts on Active Directory objects (which have object level auditing enabled) but not changes to those objects. See Directory Service Changes. Typically I recommend disabling this category and using Directory Service Changes to track actual changes. To configure this on Server 2008 you must use auditpol. Server 2008 R2 and later can use Group Policy.
Coverage on events generated by this category are currently in the Security Log Encyclopedia:
Back to top