Updated metadata

This commit is contained in:
Siddarth Mandalika 2021-10-19 09:47:15 +05:30
parent c3567ef40c
commit c34b5a85ce
810 changed files with 817 additions and 809 deletions

8
.vscode/settings.json vendored Normal file
View File

@ -0,0 +1,8 @@
{
"markdownlint.config": {
"MD028": false,
"MD025": {
"front_matter_title": ""
}
}
}

View File

@ -15,7 +15,7 @@ audience: ITPro
ms.collection: M365-security-compliance
ms.topic: conceptual
ms.date: 09/06/2021
ms.technology: mde
ms.technology: windows-sec
---
# Advanced security audit policy settings

View File

@ -16,7 +16,7 @@ metadata:
ms.collection: M365-security-compliance
ms.topic: conceptual
ms.date: 09/06/2021
ms.technology: mde
ms.technology: windows-sec
title: Advanced security auditing FAQ

View File

@ -15,7 +15,7 @@ audience: ITPro
ms.collection: M365-security-compliance
ms.topic: conceptual
ms.date: 09/6/2021
ms.technology: mde
ms.technology: windows-sec
---
# Advanced security audit policies

View File

@ -11,7 +11,7 @@ ms.date: 09/06/2021
ms.reviewer:
manager: dansimp
ms.author: dansimp
ms.technology: mde
ms.technology: windows-sec
---
# Appendix A: Security monitoring recommendations for many audit events

View File

@ -15,7 +15,7 @@ audience: ITPro
ms.collection: M365-security-compliance
ms.topic: conceptual
ms.date: 09/06/2021
ms.technology: mde
ms.technology: windows-sec
---
# Apply a basic audit policy on a file or folder

View File

@ -12,7 +12,7 @@ ms.sitesec: library
ms.localizationpriority: none
author: dansimp
ms.date: 09/06/2021
ms.technology: mde
ms.technology: windows-sec
---
# Audit Account Lockout

View File

@ -12,7 +12,7 @@ ms.sitesec: library
ms.localizationpriority: none
author: dansimp
ms.date: 09/06/2021
ms.technology: mde
ms.technology: windows-sec
---
# Audit Application Generated

View File

@ -12,7 +12,7 @@ ms.sitesec: library
ms.localizationpriority: none
author: dansimp
ms.date: 09/06/2021
ms.technology: mde
ms.technology: windows-sec
---
# Audit Application Group Management

View File

@ -12,7 +12,7 @@ ms.sitesec: library
ms.localizationpriority: none
author: dansimp
ms.date: 09/06/2021
ms.technology: mde
ms.technology: windows-sec
---
# Audit Audit Policy Change

View File

@ -12,7 +12,7 @@ ms.sitesec: library
ms.localizationpriority: none
author: dansimp
ms.date: 09/06/2021
ms.technology: mde
ms.technology: windows-sec
---
# Audit Authentication Policy Change

View File

@ -12,7 +12,7 @@ ms.sitesec: library
ms.localizationpriority: none
author: dansimp
ms.date: 09/06/2021
ms.technology: mde
ms.technology: windows-sec
---
# Audit Authorization Policy Change

View File

@ -12,7 +12,7 @@ ms.sitesec: library
ms.localizationpriority: none
author: dansimp
ms.date: 09/06/2021
ms.technology: mde
ms.technology: windows-sec
---
# Audit Central Access Policy Staging

View File

@ -12,7 +12,7 @@ ms.sitesec: library
ms.localizationpriority: none
author: dansimp
ms.date: 09/06/2021
ms.technology: mde
ms.technology: windows-sec
---
# Audit Certification Services

View File

@ -12,7 +12,7 @@ ms.sitesec: library
ms.localizationpriority: none
author: dansimp
ms.date: 09/06/2021
ms.technology: mde
ms.technology: windows-sec
---
# Audit Computer Account Management

View File

@ -12,7 +12,7 @@ ms.sitesec: library
ms.localizationpriority: none
author: dansimp
ms.date: 09/06/2021
ms.technology: mde
ms.technology: windows-sec
---
# Audit Credential Validation

View File

@ -12,7 +12,7 @@ ms.sitesec: library
ms.localizationpriority: none
author: dansimp
ms.date: 09/06/2021
ms.technology: mde
ms.technology: windows-sec
---
# Audit Detailed Directory Service Replication

View File

@ -12,7 +12,7 @@ ms.sitesec: library
ms.localizationpriority: none
author: dansimp
ms.date: 09/06/2021
ms.technology: mde
ms.technology: windows-sec
---
# Audit Detailed File Share

View File

@ -12,7 +12,7 @@ ms.sitesec: library
ms.localizationpriority: none
author: dansimp
ms.date: 09/06/2021
ms.technology: mde
ms.technology: windows-sec
---
# Audit Directory Service Access

View File

@ -12,7 +12,7 @@ ms.sitesec: library
ms.localizationpriority: none
author: dansimp
ms.date: 09/06/2021
ms.technology: mde
ms.technology: windows-sec
---
# Audit Directory Service Changes

View File

@ -12,7 +12,7 @@ ms.sitesec: library
ms.localizationpriority: none
author: dansimp
ms.date: 09/06/2021
ms.technology: mde
ms.technology: windows-sec
---
# Audit Directory Service Replication

View File

@ -12,7 +12,7 @@ ms.sitesec: library
ms.localizationpriority: none
author: dansimp
ms.date: 09/06/2021
ms.technology: mde
ms.technology: windows-sec
---
# Audit Distribution Group Management

View File

@ -12,7 +12,7 @@ ms.sitesec: library
ms.localizationpriority: none
author: dansimp
ms.date: 09/06/2021
ms.technology: mde
ms.technology: windows-sec
---
# Audit DPAPI Activity

View File

@ -12,7 +12,7 @@ ms.sitesec: library
ms.localizationpriority: none
author: dansimp
ms.date: 09/06/2021
ms.technology: mde
ms.technology: windows-sec
---
# Audit File Share

View File

@ -12,7 +12,7 @@ ms.sitesec: library
ms.localizationpriority: none
author: dansimp
ms.date: 09/06/2021
ms.technology: mde
ms.technology: windows-sec
---
# Audit File System

View File

@ -12,7 +12,7 @@ ms.sitesec: library
ms.localizationpriority: none
author: dansimp
ms.date: 09/06/2021
ms.technology: mde
ms.technology: windows-sec
---
# Audit Filtering Platform Connection

View File

@ -12,7 +12,7 @@ ms.sitesec: library
ms.localizationpriority: none
author: dansimp
ms.date: 09/06/2021
ms.technology: mde
ms.technology: windows-sec
---
# Audit Filtering Platform Packet Drop

View File

@ -12,7 +12,7 @@ ms.sitesec: library
ms.localizationpriority: none
author: dansimp
ms.date: 09/06/2021
ms.technology: mde
ms.technology: windows-sec
---
# Audit Filtering Platform Policy Change

View File

@ -12,7 +12,7 @@ ms.sitesec: library
ms.localizationpriority: none
author: dansimp
ms.date: 09/06/2021
ms.technology: mde
ms.technology: windows-sec
---
# Audit Group Membership

View File

@ -12,7 +12,7 @@ ms.sitesec: library
ms.localizationpriority: none
author: dansimp
ms.date: 09/06/2021
ms.technology: mde
ms.technology: windows-sec
---
# Audit Handle Manipulation

View File

@ -12,7 +12,7 @@ ms.sitesec: library
ms.localizationpriority: none
author: dansimp
ms.date: 09/06/2021
ms.technology: mde
ms.technology: windows-sec
---
# Audit IPsec Driver

View File

@ -12,7 +12,7 @@ ms.sitesec: library
ms.localizationpriority: none
author: dansimp
ms.date: 09/06/2021
ms.technology: mde
ms.technology: windows-sec
---
# Audit IPsec Extended Mode

View File

@ -12,7 +12,7 @@ ms.sitesec: library
ms.localizationpriority: none
author: dansimp
ms.date: 09/06/2021
ms.technology: mde
ms.technology: windows-sec
---
# Audit IPsec Main Mode

View File

@ -12,7 +12,7 @@ ms.sitesec: library
ms.localizationpriority: none
author: dansimp
ms.date: 09/06/2021
ms.technology: mde
ms.technology: windows-sec
---
# Audit IPsec Quick Mode

View File

@ -12,7 +12,7 @@ ms.sitesec: library
ms.localizationpriority: none
author: dansimp
ms.date: 09/06/2021
ms.technology: mde
ms.technology: windows-sec
---
# Audit Kerberos Authentication Service

View File

@ -12,7 +12,7 @@ ms.sitesec: library
ms.localizationpriority: none
author: dansimp
ms.date: 09/06/2021
ms.technology: mde
ms.technology: windows-sec
---
# Audit Kerberos Service Ticket Operations

View File

@ -12,7 +12,7 @@ ms.sitesec: library
ms.localizationpriority: none
author: dansimp
ms.date: 09/06/2021
ms.technology: mde
ms.technology: windows-sec
---
# Audit Kernel Object

View File

@ -12,7 +12,7 @@ ms.sitesec: library
ms.localizationpriority: none
author: dansimp
ms.date: 09/06/2021
ms.technology: mde
ms.technology: windows-sec
---
# Audit Logoff

View File

@ -12,7 +12,7 @@ ms.sitesec: library
ms.localizationpriority: none
author: dansimp
ms.date: 09/06/2021
ms.technology: mde
ms.technology: windows-sec
---
# Audit Logon

View File

@ -12,7 +12,7 @@ ms.sitesec: library
ms.localizationpriority: none
author: dansimp
ms.date: 09/06/2021
ms.technology: mde
ms.technology: windows-sec
---
# Audit MPSSVC Rule-Level Policy Change

View File

@ -12,7 +12,7 @@ ms.sitesec: library
ms.localizationpriority: none
author: dansimp
ms.date: 09/06/2021
ms.technology: mde
ms.technology: windows-sec
---
# Audit Network Policy Server

View File

@ -12,7 +12,7 @@ ms.sitesec: library
ms.localizationpriority: none
author: dansimp
ms.date: 09/06/2021
ms.technology: mde
ms.technology: windows-sec
---
# Audit Non-Sensitive Privilege Use

View File

@ -12,7 +12,7 @@ ms.sitesec: library
ms.localizationpriority: none
author: dansimp
ms.date: 09/06/2021
ms.technology: mde
ms.technology: windows-sec
---
# Audit Other Account Logon Events

View File

@ -12,7 +12,7 @@ ms.sitesec: library
ms.localizationpriority: none
author: dansimp
ms.date: 09/06/2021
ms.technology: mde
ms.technology: windows-sec
---
# Audit Other Account Management Events

View File

@ -12,7 +12,7 @@ ms.sitesec: library
ms.localizationpriority: none
author: dansimp
ms.date: 09/06/2021
ms.technology: mde
ms.technology: windows-sec
---
# Audit Other Logon/Logoff Events

View File

@ -12,7 +12,7 @@ ms.sitesec: library
ms.localizationpriority: none
author: dansimp
ms.date: 09/06/2021
ms.technology: mde
ms.technology: windows-sec
---
# Audit Other Object Access Events

View File

@ -12,7 +12,7 @@ ms.sitesec: library
ms.localizationpriority: none
author: dansimp
ms.date: 09/06/2021
ms.technology: mde
ms.technology: windows-sec
---
# Audit Other Policy Change Events

View File

@ -12,7 +12,7 @@ ms.sitesec: library
ms.localizationpriority: none
author: dansimp
ms.date: 09/06/2021
ms.technology: mde
ms.technology: windows-sec
---
# Audit Other Privilege Use Events

View File

@ -12,7 +12,7 @@ ms.sitesec: library
ms.localizationpriority: none
author: dansimp
ms.date: 09/06/2021
ms.technology: mde
ms.technology: windows-sec
---
# Audit Other System Events

View File

@ -12,7 +12,7 @@ ms.sitesec: library
ms.localizationpriority: none
author: dansimp
ms.date: 09/06/2021
ms.technology: mde
ms.technology: windows-sec
---
# Audit PNP Activity

View File

@ -12,7 +12,7 @@ ms.sitesec: library
ms.localizationpriority: none
author: dansimp
ms.date: 09/06/2021
ms.technology: mde
ms.technology: windows-sec
---
# Audit Process Creation

View File

@ -12,7 +12,7 @@ ms.sitesec: library
ms.localizationpriority: none
author: dansimp
ms.date: 09/06/2021
ms.technology: mde
ms.technology: windows-sec
---
# Audit Process Termination

View File

@ -12,7 +12,7 @@ ms.sitesec: library
ms.localizationpriority: none
author: dansimp
ms.date: 09/06/2021
ms.technology: mde
ms.technology: windows-sec
---
# Audit Registry

View File

@ -12,7 +12,7 @@ ms.sitesec: library
ms.localizationpriority: none
author: dansimp
ms.date: 09/06/2021
ms.technology: mde
ms.technology: windows-sec
---
# Audit Removable Storage

View File

@ -12,7 +12,7 @@ ms.sitesec: library
ms.localizationpriority: none
author: dansimp
ms.date: 09/06/2021
ms.technology: mde
ms.technology: windows-sec
---
# Audit RPC Events

View File

@ -12,7 +12,7 @@ ms.sitesec: library
ms.localizationpriority: none
author: dansimp
ms.date: 09/06/2021
ms.technology: mde
ms.technology: windows-sec
---
# Audit SAM

View File

@ -12,7 +12,7 @@ ms.sitesec: library
ms.localizationpriority: none
author: dansimp
ms.date: 09/06/2021
ms.technology: mde
ms.technology: windows-sec
---
# Audit Security Group Management

View File

@ -12,7 +12,7 @@ ms.sitesec: library
ms.localizationpriority: none
author: dansimp
ms.date: 09/06/2021
ms.technology: mde
ms.technology: windows-sec
---
# Audit Security State Change

View File

@ -12,7 +12,7 @@ ms.sitesec: library
ms.localizationpriority: none
author: dansimp
ms.date: 09/06/2021
ms.technology: mde
ms.technology: windows-sec
---
# Audit Security System Extension

View File

@ -12,7 +12,7 @@ ms.sitesec: library
ms.localizationpriority: none
author: dansimp
ms.date: 09/06/2021
ms.technology: mde
ms.technology: windows-sec
---
# Audit Sensitive Privilege Use

View File

@ -12,7 +12,7 @@ ms.sitesec: library
ms.localizationpriority: none
author: dansimp
ms.date: 09/06/2021
ms.technology: mde
ms.technology: windows-sec
---
# Audit Special Logon

View File

@ -12,7 +12,7 @@ ms.sitesec: library
ms.localizationpriority: none
author: dansimp
ms.date: 09/06/2021
ms.technology: mde
ms.technology: windows-sec
---
# Audit System Integrity

View File

@ -6,7 +6,7 @@ author: dansimp
ms.author: dansimp
ms.pagetype: security
ms.prod: m365-security
ms.technology: mde
ms.technology: windows-sec
---
# Audit Token Right Adjusted

View File

@ -12,7 +12,7 @@ ms.sitesec: library
ms.localizationpriority: none
author: dansimp
ms.date: 09/06/2021
ms.technology: mde
ms.technology: windows-sec
---
# Audit User Account Management

View File

@ -12,7 +12,7 @@ ms.sitesec: library
ms.localizationpriority: none
author: dansimp
ms.date: 09/06/2021
ms.technology: mde
ms.technology: windows-sec
---
# Audit User/Device Claims

View File

@ -15,7 +15,7 @@ audience: ITPro
ms.collection: M365-security-compliance
ms.topic: conceptual
ms.date: 09/06/2021
ms.technology: mde
ms.technology: windows-sec
---
# Audit account logon events

View File

@ -15,7 +15,7 @@ audience: ITPro
ms.collection: M365-security-compliance
ms.topic: conceptual
ms.date: 09/06/2021
ms.technology: mde
ms.technology: windows-sec
---
# Audit account management

View File

@ -15,7 +15,7 @@ audience: ITPro
ms.collection: M365-security-compliance
ms.topic: conceptual
ms.date: 09/06/2021
ms.technology: mde
ms.technology: windows-sec
---
# Audit directory service access

View File

@ -15,7 +15,7 @@ audience: ITPro
ms.collection: M365-security-compliance
ms.topic: conceptual
ms.date: 09/06/2021
ms.technology: mde
ms.technology: windows-sec
---
# Audit logon events

View File

@ -15,7 +15,7 @@ audience: ITPro
ms.collection: M365-security-compliance
ms.topic: conceptual
ms.date: 09/06/2021
ms.technology: mde
ms.technology: windows-sec
---
# Audit object access

View File

@ -15,7 +15,7 @@ audience: ITPro
ms.collection: M365-security-compliance
ms.topic: conceptual
ms.date: 09/06/2021
ms.technology: mde
ms.technology: windows-sec
---
# Audit policy change

View File

@ -15,7 +15,7 @@ audience: ITPro
ms.collection: M365-security-compliance
ms.topic: conceptual
ms.date: 09/06/2021
ms.technology: mde
ms.technology: windows-sec
---
# Audit privilege use

View File

@ -15,7 +15,7 @@ audience: ITPro
ms.collection: M365-security-compliance
ms.topic: conceptual
ms.date: 09/06/2021
ms.technology: mde
ms.technology: windows-sec
---
# Audit process tracking

View File

@ -15,7 +15,7 @@ audience: ITPro
ms.collection: M365-security-compliance
ms.topic: conceptual
ms.date: 09/06/2021
ms.technology: mde
ms.technology: windows-sec
---
# Audit system events

View File

@ -15,7 +15,7 @@ audience: ITPro
ms.collection: M365-security-compliance
ms.topic: conceptual
ms.date: 09/06/2021
ms.technology: mde
ms.technology: windows-sec
---
# Basic security audit policies

View File

@ -15,7 +15,7 @@ audience: ITPro
ms.collection: M365-security-compliance
ms.topic: conceptual
ms.date: 09/06/2021
ms.technology: mde
ms.technology: windows-sec
---
# Basic security audit policy settings

View File

@ -15,7 +15,7 @@ audience: ITPro
ms.collection: M365-security-compliance
ms.topic: conceptual
ms.date: 09/07/2021
ms.technology: mde
ms.technology: windows-sec
---
# Create a basic audit policy for an event category

View File

@ -11,7 +11,7 @@ ms.date: 09/07/2021
ms.reviewer:
manager: dansimp
ms.author: dansimp
ms.technology: mde
ms.technology: windows-sec
---
# 1100(S): The event logging service has shut down.

View File

@ -11,7 +11,7 @@ ms.date: 09/07/2021
ms.reviewer:
manager: dansimp
ms.author: dansimp
ms.technology: mde
ms.technology: windows-sec
---
# 1102(S): The audit log was cleared.

View File

@ -11,7 +11,7 @@ ms.date: 09/07/2021
ms.reviewer:
manager: dansimp
ms.author: dansimp
ms.technology: mde
ms.technology: windows-sec
---
# 1104(S): The security log is now full.

View File

@ -11,7 +11,7 @@ ms.date: 09/07/2021
ms.reviewer:
manager: dansimp
ms.author: dansimp
ms.technology: mde
ms.technology: windows-sec
---
# 1105(S): Event log automatic backup

View File

@ -11,7 +11,7 @@ ms.date: 09/07/2021
ms.reviewer:
manager: dansimp
ms.author: dansimp
ms.technology: mde
ms.technology: windows-sec
---
# 1108(S): The event logging service encountered an error while processing an incoming event published from %1.

View File

@ -11,7 +11,7 @@ ms.date: 09/07/2021
ms.reviewer:
manager: dansimp
ms.author: dansimp
ms.technology: mde
ms.technology: windows-sec
---
# 4608(S): Windows is starting up.

View File

@ -11,7 +11,7 @@ ms.date: 09/07/2021
ms.reviewer:
manager: dansimp
ms.author: dansimp
ms.technology: mde
ms.technology: windows-sec
---
# 4610(S): An authentication package has been loaded by the Local Security Authority.

View File

@ -11,7 +11,7 @@ ms.date: 09/07/2021
ms.reviewer:
manager: dansimp
ms.author: dansimp
ms.technology: mde
ms.technology: windows-sec
---
# 4611(S): A trusted logon process has been registered with the Local Security Authority.

View File

@ -11,7 +11,7 @@ ms.date: 09/07/2021
ms.reviewer:
manager: dansimp
ms.author: dansimp
ms.technology: mde
ms.technology: windows-sec
---
# 4612(S): Internal resources allocated for the queuing of audit messages have been exhausted, leading to the loss of some audits.

View File

@ -11,7 +11,7 @@ ms.date: 09/07/2021
ms.reviewer:
manager: dansimp
ms.author: dansimp
ms.technology: mde
ms.technology: windows-sec
---
# 4614(S): A notification package has been loaded by the Security Account Manager.

View File

@ -11,7 +11,7 @@ ms.date: 09/07/2021
ms.reviewer:
manager: dansimp
ms.author: dansimp
ms.technology: mde
ms.technology: windows-sec
---
# 4615(S): Invalid use of LPC port.

View File

@ -11,7 +11,7 @@ ms.date: 09/07/2021
ms.reviewer:
manager: dansimp
ms.author: dansimp
ms.technology: mde
ms.technology: windows-sec
---
# 4616(S): The system time was changed.

View File

@ -11,7 +11,7 @@ ms.date: 09/07/2021
ms.reviewer:
manager: dansimp
ms.author: dansimp
ms.technology: mde
ms.technology: windows-sec
---
# 4618(S): A monitored security event pattern has occurred.

View File

@ -11,7 +11,7 @@ ms.date: 09/07/2021
ms.reviewer:
manager: dansimp
ms.author: dansimp
ms.technology: mde
ms.technology: windows-sec
---
# 4621(S): Administrator recovered system from CrashOnAuditFail.

View File

@ -11,7 +11,7 @@ ms.date: 09/07/2021
ms.reviewer:
manager: dansimp
ms.author: dansimp
ms.technology: mde
ms.technology: windows-sec
---
# 4622(S): A security package has been loaded by the Local Security Authority.

View File

@ -11,7 +11,7 @@ ms.date: 09/07/2021
ms.reviewer:
manager: dansimp
ms.author: dansimp
ms.technology: mde
ms.technology: windows-sec
---
# 4624(S): An account was successfully logged on.

View File

@ -11,7 +11,7 @@ ms.date: 09/07/2021
ms.reviewer:
manager: dansimp
ms.author: dansimp
ms.technology: mde
ms.technology: windows-sec
---
# 4625(F): An account failed to log on.

View File

@ -11,7 +11,7 @@ ms.date: 09/07/2021
ms.reviewer:
manager: dansimp
ms.author: dansimp
ms.technology: mde
ms.technology: windows-sec
---
# 4626(S): User/Device claims information.

View File

@ -11,7 +11,7 @@ ms.date: 09/07/2021
ms.reviewer:
manager: dansimp
ms.author: dansimp
ms.technology: mde
ms.technology: windows-sec
---
# 4627(S): Group membership information.

View File

@ -11,7 +11,7 @@ ms.date: 09/07/2021
ms.reviewer:
manager: dansimp
ms.author: dansimp
ms.technology: mde
ms.technology: windows-sec
---
# 4634(S): An account was logged off.

View File

@ -11,7 +11,7 @@ ms.date: 09/07/2021
ms.reviewer:
manager: dansimp
ms.author: dansimp
ms.technology: mde
ms.technology: windows-sec
---
# 4647(S): User initiated logoff.

View File

@ -11,7 +11,7 @@ ms.date: 09/07/2021
ms.reviewer:
manager: dansimp
ms.author: dansimp
ms.technology: mde
ms.technology: windows-sec
---
# 4648(S): A logon was attempted using explicit credentials.

View File

@ -11,7 +11,7 @@ ms.date: 09/07/2021
ms.reviewer:
manager: dansimp
ms.author: dansimp
ms.technology: mde
ms.technology: windows-sec
---
# 4649(S): A replay attack was detected.

Some files were not shown because too many files have changed in this diff Show More