revised reg info

This commit is contained in:
Justin Hall 2017-05-25 16:59:11 -07:00
parent 39f6ca2232
commit 18a836504c

View File

@ -97,8 +97,8 @@ Audit only mode configures the SAMRPC protocol to do the access check against th
|Registry|Details| |Registry|Details|
|---|---| |---|---|
|Path|HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa| |Path|`HKEY_LOCAL_MACHINE|SYSTEM|CurrentControlSet|Control|Lsa`|
|Setting|RestrictRemoteSamAuditOnlyMode| |Setting|`RestrictRemoteSamAuditOnlyMode`|
|Data Type|REG_DWORD| |Data Type|REG_DWORD|
|Value|1| |Value|1|
|Notes|This setting cannot be added or removed by using predefined Group Policy settings. <br> Administrators may create a custom policy to set the registry value if needed. <br> SAM responds dynamically to changes in this registry value without a reboot. <br> You can use the [Events 16962 - 16969 Reader](https://gallery.technet.microsoft.com/Events-16962-16969-Reader-2eae5f1d) script to parse the event logs, as explained in the next section.| |Notes|This setting cannot be added or removed by using predefined Group Policy settings. <br> Administrators may create a custom policy to set the registry value if needed. <br> SAM responds dynamically to changes in this registry value without a reboot. <br> You can use the [Events 16962 - 16969 Reader](https://gallery.technet.microsoft.com/Events-16962-16969-Reader-2eae5f1d) script to parse the event logs, as explained in the next section.|