Merge pull request #7345 from lizgt2000/metasecurity5

meta security 5
This commit is contained in:
Thomas Raya 2022-10-25 16:22:13 -07:00 committed by GitHub
commit 9783ef0b51
No known key found for this signature in database
GPG Key ID: 4AEE18F83AFDEB23
48 changed files with 99 additions and 99 deletions

View File

@ -4,7 +4,7 @@ description: Apply audit policies to individual files and folders on your comput
ms.assetid: 565E7249-5CD0-4B2E-B2C0-B3A0793A51E2
ms.reviewer:
ms.author: vinpa
ms.prod: m365-security
ms.prod: windows-client
ms.mktglfcycl: deploy
ms.sitesec: library
ms.pagetype: security
@ -15,7 +15,7 @@ audience: ITPro
ms.collection: M365-security-compliance
ms.topic: conceptual
ms.date: 09/06/2021
ms.technology: windows-sec
ms.technology: itpro-security
---
# Apply a basic audit policy on a file or folder

View File

@ -6,13 +6,13 @@ ms.reviewer:
manager: aaroncz
ms.author: vinpa
ms.pagetype: security
ms.prod: m365-security
ms.prod: windows-client
ms.mktglfcycl: deploy
ms.sitesec: library
ms.localizationpriority: none
author: vinaypamnani-msft
ms.date: 09/06/2021
ms.technology: windows-sec
ms.technology: itpro-security
---
# Audit Account Lockout

View File

@ -6,13 +6,13 @@ ms.reviewer:
manager: aaroncz
ms.author: vinpa
ms.pagetype: security
ms.prod: m365-security
ms.prod: windows-client
ms.mktglfcycl: deploy
ms.sitesec: library
ms.localizationpriority: none
author: vinaypamnani-msft
ms.date: 09/06/2021
ms.technology: windows-sec
ms.technology: itpro-security
---
# Audit Application Generated

View File

@ -6,13 +6,13 @@ ms.reviewer:
manager: aaroncz
ms.author: vinpa
ms.pagetype: security
ms.prod: m365-security
ms.prod: windows-client
ms.mktglfcycl: deploy
ms.sitesec: library
ms.localizationpriority: none
author: vinaypamnani-msft
ms.date: 09/06/2021
ms.technology: windows-sec
ms.technology: itpro-security
---
# Audit Application Group Management

View File

@ -6,13 +6,13 @@ ms.reviewer:
manager: aaroncz
ms.author: vinpa
ms.pagetype: security
ms.prod: m365-security
ms.prod: windows-client
ms.mktglfcycl: deploy
ms.sitesec: library
ms.localizationpriority: none
author: vinaypamnani-msft
ms.date: 09/06/2021
ms.technology: windows-sec
ms.technology: itpro-security
---
# Audit Audit Policy Change

View File

@ -6,13 +6,13 @@ ms.reviewer:
manager: aaroncz
ms.author: vinpa
ms.pagetype: security
ms.prod: m365-security
ms.prod: windows-client
ms.mktglfcycl: deploy
ms.sitesec: library
ms.localizationpriority: none
author: vinaypamnani-msft
ms.date: 09/06/2021
ms.technology: windows-sec
ms.technology: itpro-security
---
# Audit Authentication Policy Change

View File

@ -6,13 +6,13 @@ ms.reviewer:
manager: aaroncz
ms.author: vinpa
ms.pagetype: security
ms.prod: m365-security
ms.prod: windows-client
ms.mktglfcycl: deploy
ms.sitesec: library
ms.localizationpriority: none
author: vinaypamnani-msft
ms.date: 09/06/2021
ms.technology: windows-sec
ms.technology: itpro-security
---
# Audit Authorization Policy Change

View File

@ -6,13 +6,13 @@ ms.reviewer:
manager: aaroncz
ms.author: vinpa
ms.pagetype: security
ms.prod: m365-security
ms.prod: windows-client
ms.mktglfcycl: deploy
ms.sitesec: library
ms.localizationpriority: none
author: vinaypamnani-msft
ms.date: 09/06/2021
ms.technology: windows-sec
ms.technology: itpro-security
---
# Audit Central Access Policy Staging

View File

@ -6,13 +6,13 @@ ms.reviewer:
manager: aaroncz
ms.author: vinpa
ms.pagetype: security
ms.prod: m365-security
ms.prod: windows-client
ms.mktglfcycl: deploy
ms.sitesec: library
ms.localizationpriority: none
author: vinaypamnani-msft
ms.date: 09/06/2021
ms.technology: windows-sec
ms.technology: itpro-security
---
# Audit Certification Services

View File

@ -6,13 +6,13 @@ ms.reviewer:
manager: aaroncz
ms.author: vinpa
ms.pagetype: security
ms.prod: m365-security
ms.prod: windows-client
ms.mktglfcycl: deploy
ms.sitesec: library
ms.localizationpriority: none
author: vinaypamnani-msft
ms.date: 09/06/2021
ms.technology: windows-sec
ms.technology: itpro-security
---
# Audit Computer Account Management

View File

@ -6,13 +6,13 @@ ms.reviewer:
manager: aaroncz
ms.author: vinpa
ms.pagetype: security
ms.prod: m365-security
ms.prod: windows-client
ms.mktglfcycl: deploy
ms.sitesec: library
ms.localizationpriority: none
author: vinaypamnani-msft
ms.date: 09/06/2021
ms.technology: windows-sec
ms.technology: itpro-security
---
# Audit Credential Validation

View File

@ -6,13 +6,13 @@ ms.reviewer:
manager: aaroncz
ms.author: vinpa
ms.pagetype: security
ms.prod: m365-security
ms.prod: windows-client
ms.mktglfcycl: deploy
ms.sitesec: library
ms.localizationpriority: none
author: vinaypamnani-msft
ms.date: 09/06/2021
ms.technology: windows-sec
ms.technology: itpro-security
---
# Audit Detailed Directory Service Replication

View File

@ -6,13 +6,13 @@ ms.reviewer:
manager: aaroncz
ms.author: vinpa
ms.pagetype: security
ms.prod: m365-security
ms.prod: windows-client
ms.mktglfcycl: deploy
ms.sitesec: library
ms.localizationpriority: none
author: vinaypamnani-msft
ms.date: 09/06/2021
ms.technology: windows-sec
ms.technology: itpro-security
---
# Audit Detailed File Share
@ -34,9 +34,9 @@ There are no system access control lists (SACLs) for shared folders. If this pol
| Computer Type | General Success | General Failure | Stronger Success | Stronger Failure | Comments |
|-------------------|-----------------|-----------------|------------------|------------------|--------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------|
| Domain Controller | No | Yes | No | Yes | Audit Success for this subcategory on domain controllers typically will lead to high volume of events, especially for SYSVOL share.<br>We recommend monitoring Failure access attempts: the volume should not be high. You will be able to see who was not able to get access to a file or folder on a network share on a computer. |
| Member Server | IF | Yes | IF | Yes | IF If a server has shared network folders that typically get many access requests (File Server, for example), the volume of events might be high. If you really need to track all successful access events for every file or folder located on a shared folder, enable Success auditing or use the [Audit File System](audit-file-system.md) subcategory, although that subcategory excludes some information in Audit Detailed File Share, for example, the clients IP address.<br>The volume of Failure events for member servers should not be high (if they are not File Servers). With Failure auditing, you can see who can't access a file or folder on a network share on this computer. |
| Workstation | IF | Yes | IF | Yes | IF If a workstation has shared network folders that typically get many access requests, the volume of events might be high. If you really need to track all successful access events for every file or folder located on a shared folder, enable Success auditing or use Audit File System subcategory, although that subcategory excludes some information in Audit Detailed File Share, for example, the clients IP address.<br>The volume of Failure events for workstations should not be high. With Failure auditing, you can see who can't access a file or folder on a network share on this computer. |
| Domain Controller | No | Yes | No | Yes | Audit Success for this subcategory on domain controllers typically will lead to high volume of events, especially for SYSVOL share.<br>We recommend monitoring Failure access attempts: the volume shouldn't be high. You will be able to see who wasn't able to get access to a file or folder on a network share on a computer. |
| Member Server | IF | Yes | IF | Yes | IF If a server has shared network folders that typically get many access requests (File Server, for example), the volume of events might be high. If you really need to track all successful access events for every file or folder located on a shared folder, enable Success auditing or use the [Audit File System](audit-file-system.md) subcategory, although that subcategory excludes some information in Audit Detailed File Share, for example, the clients IP address.<br>The volume of Failure events for member servers shouldn't be high (if they aren't File Servers). With Failure auditing, you can see who can't access a file or folder on a network share on this computer. |
| Workstation | IF | Yes | IF | Yes | IF If a workstation has shared network folders that typically get many access requests, the volume of events might be high. If you really need to track all successful access events for every file or folder located on a shared folder, enable Success auditing or use Audit File System subcategory, although that subcategory excludes some information in Audit Detailed File Share, for example, the clients IP address.<br>The volume of Failure events for workstations shouldn't be high. With Failure auditing, you can see who can't access a file or folder on a network share on this computer. |
**Events List:**

View File

@ -6,13 +6,13 @@ ms.reviewer:
manager: aaroncz
ms.author: vinpa
ms.pagetype: security
ms.prod: m365-security
ms.prod: windows-client
ms.mktglfcycl: deploy
ms.sitesec: library
ms.localizationpriority: none
author: vinaypamnani-msft
ms.date: 09/06/2021
ms.technology: windows-sec
ms.technology: itpro-security
---
# Audit Directory Service Access

View File

@ -6,13 +6,13 @@ ms.reviewer:
manager: aaroncz
ms.author: vinpa
ms.pagetype: security
ms.prod: m365-security
ms.prod: windows-client
ms.mktglfcycl: deploy
ms.sitesec: library
ms.localizationpriority: none
author: vinaypamnani-msft
ms.date: 09/06/2021
ms.technology: windows-sec
ms.technology: itpro-security
---
# Audit Directory Service Changes

View File

@ -6,13 +6,13 @@ ms.reviewer:
manager: aaroncz
ms.author: vinpa
ms.pagetype: security
ms.prod: m365-security
ms.prod: windows-client
ms.mktglfcycl: deploy
ms.sitesec: library
ms.localizationpriority: none
author: vinaypamnani-msft
ms.date: 09/06/2021
ms.technology: windows-sec
ms.technology: itpro-security
---
# Audit Directory Service Replication

View File

@ -6,13 +6,13 @@ ms.reviewer:
manager: aaroncz
ms.author: vinpa
ms.pagetype: security
ms.prod: m365-security
ms.prod: windows-client
ms.mktglfcycl: deploy
ms.sitesec: library
ms.localizationpriority: none
author: vinaypamnani-msft
ms.date: 09/06/2021
ms.technology: windows-sec
ms.technology: itpro-security
---
# Audit Distribution Group Management

View File

@ -6,13 +6,13 @@ ms.reviewer:
manager: aaroncz
ms.author: vinpa
ms.pagetype: security
ms.prod: m365-security
ms.prod: windows-client
ms.mktglfcycl: deploy
ms.sitesec: library
ms.localizationpriority: none
author: vinaypamnani-msft
ms.date: 09/06/2021
ms.technology: windows-sec
ms.technology: itpro-security
---
# Audit DPAPI Activity

View File

@ -6,13 +6,13 @@ ms.reviewer:
manager: aaroncz
ms.author: vinpa
ms.pagetype: security
ms.prod: m365-security
ms.prod: windows-client
ms.mktglfcycl: deploy
ms.sitesec: library
ms.localizationpriority: none
author: vinaypamnani-msft
ms.date: 09/06/2021
ms.technology: windows-sec
ms.technology: itpro-security
---
# Audit File Share

View File

@ -6,13 +6,13 @@ ms.reviewer:
manager: aaroncz
ms.author: vinpa
ms.pagetype: security
ms.prod: m365-security
ms.prod: windows-client
ms.mktglfcycl: deploy
ms.sitesec: library
ms.localizationpriority: none
author: vinaypamnani-msft
ms.date: 09/06/2021
ms.technology: windows-sec
ms.technology: itpro-security
---
# Audit File System

View File

@ -6,13 +6,13 @@ ms.reviewer:
manager: aaroncz
ms.author: vinpa
ms.pagetype: security
ms.prod: m365-security
ms.prod: windows-client
ms.mktglfcycl: deploy
ms.sitesec: library
ms.localizationpriority: none
author: vinaypamnani-msft
ms.date: 09/06/2021
ms.technology: windows-sec
ms.technology: itpro-security
---
# Audit Filtering Platform Connection

View File

@ -6,13 +6,13 @@ ms.reviewer:
manager: aaroncz
ms.author: vinpa
ms.pagetype: security
ms.prod: m365-security
ms.prod: windows-client
ms.mktglfcycl: deploy
ms.sitesec: library
ms.localizationpriority: none
author: vinaypamnani-msft
ms.date: 09/06/2021
ms.technology: windows-sec
ms.technology: itpro-security
---
# Audit Filtering Platform Packet Drop

View File

@ -6,13 +6,13 @@ ms.reviewer:
manager: aaroncz
ms.author: vinpa
ms.pagetype: security
ms.prod: m365-security
ms.prod: windows-client
ms.mktglfcycl: deploy
ms.sitesec: library
ms.localizationpriority: none
author: vinaypamnani-msft
ms.date: 09/06/2021
ms.technology: windows-sec
ms.technology: itpro-security
---
# Audit Filtering Platform Policy Change

View File

@ -6,13 +6,13 @@ ms.reviewer:
manager: aaroncz
ms.author: vinpa
ms.pagetype: security
ms.prod: m365-security
ms.prod: windows-client
ms.mktglfcycl: deploy
ms.sitesec: library
ms.localizationpriority: none
author: vinaypamnani-msft
ms.date: 09/06/2021
ms.technology: windows-sec
ms.technology: itpro-security
---
# Audit Group Membership

View File

@ -6,13 +6,13 @@ ms.reviewer:
manager: aaroncz
ms.author: vinpa
ms.pagetype: security
ms.prod: m365-security
ms.prod: windows-client
ms.mktglfcycl: deploy
ms.sitesec: library
ms.localizationpriority: none
author: vinaypamnani-msft
ms.date: 09/06/2021
ms.technology: windows-sec
ms.technology: itpro-security
---
# Audit Handle Manipulation

View File

@ -6,13 +6,13 @@ ms.reviewer:
manager: aaroncz
ms.author: vinpa
ms.pagetype: security
ms.prod: m365-security
ms.prod: windows-client
ms.mktglfcycl: deploy
ms.sitesec: library
ms.localizationpriority: none
author: vinaypamnani-msft
ms.date: 09/06/2021
ms.technology: windows-sec
ms.technology: itpro-security
---
# Audit IPsec Driver

View File

@ -6,13 +6,13 @@ ms.reviewer:
manager: aaroncz
ms.author: vinpa
ms.pagetype: security
ms.prod: m365-security
ms.prod: windows-client
ms.mktglfcycl: deploy
ms.sitesec: library
ms.localizationpriority: none
author: vinaypamnani-msft
ms.date: 09/06/2021
ms.technology: windows-sec
ms.technology: itpro-security
---
# Audit IPsec Extended Mode

View File

@ -6,13 +6,13 @@ ms.reviewer:
manager: aaroncz
ms.author: vinpa
ms.pagetype: security
ms.prod: m365-security
ms.prod: windows-client
ms.mktglfcycl: deploy
ms.sitesec: library
ms.localizationpriority: none
author: vinaypamnani-msft
ms.date: 09/06/2021
ms.technology: windows-sec
ms.technology: itpro-security
---
# Audit IPsec Main Mode

View File

@ -6,13 +6,13 @@ ms.reviewer:
manager: aaroncz
ms.author: vinpa
ms.pagetype: security
ms.prod: m365-security
ms.prod: windows-client
ms.mktglfcycl: deploy
ms.sitesec: library
ms.localizationpriority: none
author: vinaypamnani-msft
ms.date: 09/06/2021
ms.technology: windows-sec
ms.technology: itpro-security
---
# Audit IPsec Quick Mode

View File

@ -6,13 +6,13 @@ ms.reviewer:
manager: aaroncz
ms.author: vinpa
ms.pagetype: security
ms.prod: m365-security
ms.prod: windows-client
ms.mktglfcycl: deploy
ms.sitesec: library
ms.localizationpriority: none
author: vinaypamnani-msft
ms.date: 09/06/2021
ms.technology: windows-sec
ms.technology: itpro-security
---
# Audit Kerberos Authentication Service

View File

@ -6,13 +6,13 @@ ms.reviewer:
manager: aaroncz
ms.author: vinpa
ms.pagetype: security
ms.prod: m365-security
ms.prod: windows-client
ms.mktglfcycl: deploy
ms.sitesec: library
ms.localizationpriority: none
author: vinaypamnani-msft
ms.date: 09/06/2021
ms.technology: windows-sec
ms.technology: itpro-security
---
# Audit Kerberos Service Ticket Operations

View File

@ -6,13 +6,13 @@ ms.reviewer:
manager: aaroncz
ms.author: vinpa
ms.pagetype: security
ms.prod: m365-security
ms.prod: windows-client
ms.mktglfcycl: deploy
ms.sitesec: library
ms.localizationpriority: none
author: vinaypamnani-msft
ms.date: 09/06/2021
ms.technology: windows-sec
ms.technology: itpro-security
---
# Audit Kernel Object

View File

@ -6,13 +6,13 @@ ms.reviewer:
manager: aaroncz
ms.author: vinpa
ms.pagetype: security
ms.prod: m365-security
ms.prod: windows-client
ms.mktglfcycl: deploy
ms.sitesec: library
ms.localizationpriority: none
author: vinaypamnani-msft
ms.date: 09/06/2021
ms.technology: windows-sec
ms.technology: itpro-security
---
# Audit Logoff

View File

@ -6,13 +6,13 @@ ms.reviewer:
manager: aaroncz
ms.author: vinpa
ms.pagetype: security
ms.prod: m365-security
ms.prod: windows-client
ms.mktglfcycl: deploy
ms.sitesec: library
ms.localizationpriority: none
author: vinaypamnani-msft
ms.date: 09/06/2021
ms.technology: windows-sec
ms.technology: itpro-security
---
# Audit Logon

View File

@ -6,13 +6,13 @@ ms.reviewer:
manager: aaroncz
ms.author: vinpa
ms.pagetype: security
ms.prod: m365-security
ms.prod: windows-client
ms.mktglfcycl: deploy
ms.sitesec: library
ms.localizationpriority: none
author: vinaypamnani-msft
ms.date: 09/06/2021
ms.technology: windows-sec
ms.technology: itpro-security
---
# Audit MPSSVC Rule-Level Policy Change

View File

@ -6,13 +6,13 @@ ms.reviewer:
manager: aaroncz
ms.author: vinpa
ms.pagetype: security
ms.prod: m365-security
ms.prod: windows-client
ms.mktglfcycl: deploy
ms.sitesec: library
ms.localizationpriority: none
author: vinaypamnani-msft
ms.date: 09/06/2021
ms.technology: windows-sec
ms.technology: itpro-security
---
# Audit Network Policy Server

View File

@ -6,13 +6,13 @@ ms.reviewer:
manager: aaroncz
ms.author: vinpa
ms.pagetype: security
ms.prod: m365-security
ms.prod: windows-client
ms.mktglfcycl: deploy
ms.sitesec: library
ms.localizationpriority: none
author: vinaypamnani-msft
ms.date: 09/06/2021
ms.technology: windows-sec
ms.technology: itpro-security
---
# Audit Non-Sensitive Privilege Use

View File

@ -6,13 +6,13 @@ ms.reviewer:
manager: aaroncz
ms.author: vinpa
ms.pagetype: security
ms.prod: m365-security
ms.prod: windows-client
ms.mktglfcycl: deploy
ms.sitesec: library
ms.localizationpriority: none
author: vinaypamnani-msft
ms.date: 09/06/2021
ms.technology: windows-sec
ms.technology: itpro-security
---
# Audit Other Account Logon Events

View File

@ -6,13 +6,13 @@ ms.reviewer:
manager: aaroncz
ms.author: vinpa
ms.pagetype: security
ms.prod: m365-security
ms.prod: windows-client
ms.mktglfcycl: deploy
ms.sitesec: library
ms.localizationpriority: none
author: vinaypamnani-msft
ms.date: 09/06/2021
ms.technology: windows-sec
ms.technology: itpro-security
---
# Audit Other Account Management Events

View File

@ -6,13 +6,13 @@ ms.reviewer:
manager: aaroncz
ms.author: vinpa
ms.pagetype: security
ms.prod: m365-security
ms.prod: windows-client
ms.mktglfcycl: deploy
ms.sitesec: library
ms.localizationpriority: none
author: vinaypamnani-msft
ms.date: 09/06/2021
ms.technology: windows-sec
ms.technology: itpro-security
---
# Audit Other Logon/Logoff Events

View File

@ -6,13 +6,13 @@ ms.reviewer:
manager: aaroncz
ms.author: vinpa
ms.pagetype: security
ms.prod: m365-security
ms.prod: windows-client
ms.mktglfcycl: deploy
ms.sitesec: library
ms.localizationpriority: none
author: vinaypamnani-msft
ms.date: 09/06/2021
ms.technology: windows-sec
ms.technology: itpro-security
---
# Audit Other Object Access Events

View File

@ -6,13 +6,13 @@ ms.reviewer:
manager: aaroncz
ms.author: vinpa
ms.pagetype: security
ms.prod: m365-security
ms.prod: windows-client
ms.mktglfcycl: deploy
ms.sitesec: library
ms.localizationpriority: none
author: vinaypamnani-msft
ms.date: 09/06/2021
ms.technology: windows-sec
ms.technology: itpro-security
---
# Audit Other Policy Change Events

View File

@ -6,13 +6,13 @@ ms.reviewer:
manager: aaroncz
ms.author: vinpa
ms.pagetype: security
ms.prod: m365-security
ms.prod: windows-client
ms.mktglfcycl: deploy
ms.sitesec: library
ms.localizationpriority: none
author: vinaypamnani-msft
ms.date: 09/06/2021
ms.technology: windows-sec
ms.technology: itpro-security
---
# Audit Other Privilege Use Events

View File

@ -6,13 +6,13 @@ ms.reviewer:
manager: aaroncz
ms.author: vinpa
ms.pagetype: security
ms.prod: m365-security
ms.prod: windows-client
ms.mktglfcycl: deploy
ms.sitesec: library
ms.localizationpriority: none
author: vinaypamnani-msft
ms.date: 09/06/2021
ms.technology: windows-sec
ms.technology: itpro-security
---
# Audit Other System Events

View File

@ -6,13 +6,13 @@ ms.reviewer:
manager: aaroncz
ms.author: vinpa
ms.pagetype: security
ms.prod: m365-security
ms.prod: windows-client
ms.mktglfcycl: deploy
ms.sitesec: library
ms.localizationpriority: none
author: vinaypamnani-msft
ms.date: 09/06/2021
ms.technology: windows-sec
ms.technology: itpro-security
---
# Audit PNP Activity

View File

@ -6,13 +6,13 @@ ms.reviewer:
manager: aaroncz
ms.author: vinpa
ms.pagetype: security
ms.prod: m365-security
ms.prod: windows-client
ms.mktglfcycl: deploy
ms.sitesec: library
ms.localizationpriority: none
author: vinaypamnani-msft
ms.date: 03/16/2022
ms.technology: windows-sec
ms.technology: itpro-security
---
# Audit Process Creation

View File

@ -6,13 +6,13 @@ ms.reviewer:
manager: aaroncz
ms.author: vinpa
ms.pagetype: security
ms.prod: m365-security
ms.prod: windows-client
ms.mktglfcycl: deploy
ms.sitesec: library
ms.localizationpriority: none
author: vinaypamnani-msft
ms.date: 09/06/2021
ms.technology: windows-sec
ms.technology: itpro-security
---
# Audit Process Termination

View File

@ -6,13 +6,13 @@ ms.reviewer:
manager: aaroncz
ms.author: vinpa
ms.pagetype: security
ms.prod: m365-security
ms.prod: windows-client
ms.mktglfcycl: deploy
ms.sitesec: library
ms.localizationpriority: none
author: vinaypamnani-msft
ms.date: 01/05/2021
ms.technology: windows-sec
ms.technology: itpro-security
---
# Audit Registry