From 3231ccf3f55fa10e6732f86c4af21ec8ccf12e25 Mon Sep 17 00:00:00 2001 From: Liz Long <104389055+lizgt2000@users.noreply.github.com> Date: Mon, 9 Jan 2023 14:48:56 -0500 Subject: [PATCH] add volume to audit --- .../client-management/mdm/policy-csp-audit.md | 56 +++++++++++++++++++ 1 file changed, 56 insertions(+) diff --git a/windows/client-management/mdm/policy-csp-audit.md b/windows/client-management/mdm/policy-csp-audit.md index c039ded0e0..b2e381fcca 100644 --- a/windows/client-management/mdm/policy-csp-audit.md +++ b/windows/client-management/mdm/policy-csp-audit.md @@ -42,6 +42,7 @@ This policy setting allows you to audit events generated by validation tests on +Volume: High on domain controllers. @@ -102,6 +103,7 @@ This policy setting allows you to audit events generated by Kerberos authenticat +Volume: High on Kerberos Key Distribution Center servers. @@ -162,6 +164,7 @@ This policy setting allows you to audit events generated by Kerberos authenticat +Volume: Low. @@ -282,6 +285,7 @@ This policy setting allows you to audit events generated by a failed attempt to +Volume: Low. @@ -342,6 +346,7 @@ This policy allows you to audit the group memberhsip information in the user's l +Volume: Low on a client computer. Medium on a domain controller or a network server. @@ -402,6 +407,7 @@ This policy setting allows you to audit events generated by Internet Key Exchang +Volume: High. @@ -462,6 +468,7 @@ This policy setting allows you to audit events generated by Internet Key Exchang +Volume: High. @@ -522,6 +529,7 @@ This policy setting allows you to audit events generated by Internet Key Exchang +Volume: High. @@ -582,6 +590,7 @@ This policy setting allows you to audit events generated by the closing of a log +Volume: Low. @@ -642,6 +651,7 @@ This policy setting allows you to audit events generated by user account logon a +Volume: Low on a client computer. Medium on a domain controller or a network server. @@ -702,6 +712,7 @@ This policy setting allows you to audit events generated by RADIUS (IAS) and Net +Volume: Medium or High on NPS and IAS server. No volume on other computers. @@ -762,6 +773,7 @@ This policy setting allows you to audit other logon/logoff-related events that a +Volume: Low. @@ -822,6 +834,7 @@ This policy setting allows you to audit events generated by special logons such +Volume: Low. @@ -882,6 +895,7 @@ This policy allows you to audit user and device claims information in the user's +Volume: Low on a client computer. Medium on a domain controller or a network server. @@ -942,6 +956,7 @@ This policy setting allows you to audit events generated by changes to applicati +Volume: Low. @@ -1002,6 +1017,7 @@ This policy setting allows you to audit events generated by changes to computer +Volume: Low. @@ -1064,6 +1080,7 @@ This policy setting allows you to audit events generated by changes to distribut +Volume: Low. @@ -1124,6 +1141,7 @@ This policy setting allows you to audit events generated by other user account c +Volume: Low. @@ -1184,6 +1202,7 @@ This policy setting allows you to audit events generated by changes to security +Volume: Low. @@ -1244,6 +1263,7 @@ This policy setting allows you to audit changes to user accounts. Events include +Volume: Low. @@ -1304,6 +1324,7 @@ This policy setting allows you to audit events generated when encryption or decr +Volume: Low. @@ -1364,6 +1385,7 @@ This policy setting allows you to audit when plug and play detects an external d +Volume: Low. @@ -1424,6 +1446,7 @@ This policy setting allows you to audit events generated when a process is creat +Volume: Depends on how the computer is used. @@ -1484,6 +1507,7 @@ This policy setting allows you to audit events generated when a process ends. If +Volume: Depends on how the computer is used. @@ -1544,6 +1568,7 @@ This policy setting allows you to audit inbound remote procedure call (RPC) conn +Volume: High on RPC servers. @@ -1604,6 +1629,7 @@ This policy setting allows you to audit events generated by adjusting the privil +Volume: High. @@ -1664,6 +1690,7 @@ This policy setting allows you to audit events generated by detailed Active Dire +Volume: High. @@ -1724,6 +1751,7 @@ This policy setting allows you to audit events generated when an Active Director +Volume: High on domain controllers. None on client computers. @@ -1786,6 +1814,7 @@ This policy setting allows you to audit events generated by changes to objects i +Volume: High on domain controllers only. @@ -1846,6 +1875,7 @@ This policy setting allows you to audit replication between two Active Directory +Volume: Medium on domain controllers. None on client computers. @@ -1906,6 +1936,7 @@ This policy setting allows you to audit applications that generate events using +Volume: Depends on the applications that are generating them. @@ -1966,6 +1997,7 @@ This policy setting allows you to audit access requests where the permission gra +Volume: Potentially high on a file server when the proposed policy differs significantly from the current central access policy. @@ -2026,6 +2058,7 @@ This policy setting allows you to audit Active Directory Certificate Services (A +Volume: Medium or Low on computers running Active Directory Certificate Services. @@ -2088,6 +2121,7 @@ This policy setting allows you to audit attempts to access files and folders on +Volume: High on a file server or domain controller because of SYSVOL network access required by Group Policy. @@ -2150,6 +2184,7 @@ This policy setting allows you to audit attempts to access a shared folder. If y +Volume: High on a file server or domain controller because of SYSVOL network access required by Group Policy. @@ -2212,6 +2247,7 @@ This policy setting allows you to audit user attempts to access file system obje +Volume: Depends on how the file system SACLs are configured. @@ -2272,6 +2308,7 @@ This policy setting allows you to audit connections that are allowed or blocked +Volume: High. @@ -2332,6 +2369,7 @@ This policy setting allows you to audit packets that are dropped by Windows Filt +Volume: High. @@ -2394,6 +2432,7 @@ This policy setting allows you to audit events generated when a handle to an obj +Volume: Depends on how SACLs are configured. @@ -2456,6 +2495,7 @@ This policy setting allows you to audit attempts to access the kernel, which inc +Volume: High if auditing access of global system objects is enabled. @@ -2516,6 +2556,7 @@ This policy setting allows you to audit events generated by the management of ta +Volume: Low. @@ -2578,6 +2619,7 @@ This policy setting allows you to audit attempts to access registry objects. A s +Volume: Depends on how registry SACLs are configured. @@ -2700,6 +2742,7 @@ This policy setting allows you to audit events generated by attempts to access t +Volume: High on domain controllers. For more information about reducing the number of events generated by auditing the access of global system objects, see [Audit the access of global system objects](/windows/security/threat-protection/security-policy-settings/audit-audit-the-access-of-global-system-objects). @@ -2762,6 +2805,7 @@ This policy setting allows you to audit events generated by changes to the authe +Volume: Low. @@ -2822,6 +2866,7 @@ This policy setting allows you to audit events generated by changes to the autho +Volume: Low. @@ -2882,6 +2927,7 @@ This policy setting allows you to audit events generated by changes to the Windo +Volume: Low. @@ -2942,6 +2988,7 @@ This policy setting allows you to audit events generated by changes in policy ru +Volume: Low. @@ -3002,6 +3049,7 @@ This policy setting allows you to audit events generated by other security polic +Volume: Low. @@ -3064,6 +3112,7 @@ This policy setting allows you to audit changes in the security audit policy set +Volume: Low. @@ -3124,6 +3173,7 @@ This policy setting allows you to audit events generated by the use of non-sensi +Volume: Very High. @@ -3244,6 +3294,7 @@ This policy setting allows you to audit events generated when sensitive privileg +Volume: High. @@ -3304,6 +3355,7 @@ This policy setting allows you to audit events generated by the IPsec filter dri +Volume: Low. @@ -3364,6 +3416,7 @@ This policy setting allows you to audit any of the following events: Startup and +Volume: Low. @@ -3424,6 +3477,7 @@ This policy setting allows you to audit events generated by changes in the secur +Volume: Low. @@ -3484,6 +3538,7 @@ This policy setting allows you to audit events related to security system extens +Volume: Low. Security system extension events are generated more often on a domain controller than on client computers or member servers. @@ -3544,6 +3599,7 @@ This policy setting allows you to audit events that violate the integrity of the +Volume: Low.