Skip to content

Auditing Active Directory: audit policy, key events and forwarding

Configure advanced audit policy without clashing with basic audit settings, audit directory changes with SACLs, recognize the events that matter for accounts, groups, sign-in and policy changes, and get them off the domain controllers into a collector or SIEM before they're overwritten.

Level
Intermediate
Length
About 60 minutes
Contents
3 lessons · final exam
Status
Published · updated 1 Oct 2026

Skills you'll practise

  • Configure advanced audit policy through Group Policy and explain why basic and advanced settings shouldn't be mixed
  • Explain why Directory Service Changes events need both the audit subcategory and SACLs on the objects
  • Identify the event IDs for account, group-membership, sign-in, lockout, audit-policy and directory changes
  • Choose what to collect and where to forward it so events survive log rollover
  • Investigate a privileged group change from the events and write up who changed what and when

Course outline

  1. 1.Audit policy: basic, advanced and the force settingLesson · 15 min
  2. 2.Directory changes, SACLs and the events that matterLesson · 18 min
  3. 3.Keeping events: log size, forwarding and reviewsLesson · 15 min
  4. 4.Auditing Active Directory: audit policy, key events and forwarding: knowledge checkKnowledge check · 14 questions
  5. 5.Auditing Active Directory: audit policy, key events and forwarding: practical exerciseKnowledge check · 1 question
  6. 6.Final exam10 questions · passing it completes the course, so people who already know the material can test out

Sources it draws on

The lessons and questions are written from these references, so learners can go back to the original.

See it with your own jobs and topics

Tell us about your team and we'll walk you through setup, from choosing jobs to your first skills check.