Enable audit logging for privileged group membership changes
LowCompleted
Configured Windows audit policy to log all changes to Domain Admins, Enterprise Admins, and Schema Admins groups. Logs forwarding to SIEM.
Expected Impact
No operational impact. Slight increase in event log volume (~2%).
- Service
- AD-SERVER-01
- Host
- AD-SERVER-01prod
- Completed At
- Mar 31, 2026, 10:00 AM
- Logged By
- Sam Patel
- Created
- Mar 31, 2026
active-directoryauditcompliancesiem
Status updates are disabled in demo mode.