Auditing Active Directory: audit policy, key events and forwarding
Configure advanced audit policy without clashing with basic audit settings, audit directory changes with SACLs, recognize the events that matter for accounts, groups, sign-in and policy changes, and get them off the domain controllers into a collector or SIEM before they're overwritten.
- Level
- Intermediate
- Length
- About 60 minutes
- Contents
- 3 lessons · final exam
- Status
- Published · updated 1 Oct 2026
Skills you'll practise
- Configure advanced audit policy through Group Policy and explain why basic and advanced settings shouldn't be mixed
- Explain why Directory Service Changes events need both the audit subcategory and SACLs on the objects
- Identify the event IDs for account, group-membership, sign-in, lockout, audit-policy and directory changes
- Choose what to collect and where to forward it so events survive log rollover
- Investigate a privileged group change from the events and write up who changed what and when
Course outline
- 1.Audit policy: basic, advanced and the force settingLesson · 15 min
- 2.Directory changes, SACLs and the events that matterLesson · 18 min
- 3.Keeping events: log size, forwarding and reviewsLesson · 15 min
- 4.Auditing Active Directory: audit policy, key events and forwarding: knowledge checkKnowledge check · 14 questions
- 5.Auditing Active Directory: audit policy, key events and forwarding: practical exerciseKnowledge check · 1 question
- 6.Final exam10 questions · passing it completes the course, so people who already know the material can test out
Sources it draws on
The lessons and questions are written from these references, so learners can go back to the original.
- Microsoft Learn: Advanced security audit policy settings
- Microsoft Learn: Advanced Security Auditing FAQ
- Microsoft Learn: Security auditing settings are not applied when you deploy a domain-based policy
- Microsoft Learn: Audit Directory Service Changes
- Microsoft Learn: Appendix L: Events to monitor
- Microsoft Learn: 4740(S) A user account was locked out
- Microsoft Learn: Use Windows Event Forwarding to help with intrusion detection
- Microsoft Learn: Implementing least-privilege administrative models
See it with your own jobs and topics
Tell us about your team and we'll walk you through setup, from choosing jobs to your first skills check.