How to enable audit policies required for the initiator detection
To enable audit policies required for the initiator detection:
From the Domain Controller, navigate to Start > Administrative Tools > Group Policy Management.
From the console tree, click the name of your forest > Domains > your domain. Right-click the relevant Default Domain or Domain Controllers Policy (or create your own policy), and then click Edit.
Under Computer Configuration, click Policies > Windows Settings > Security Settings > Advanced Audit Policy Configuration > Audit Policy, then double-click the relevant policy setting.
Enable the following policies for Cayosoft Guardian:
Select the Logon/Logoff policy and enable Success events for the Audit Account Lockout subcategory.
Select the Account Management policy and enable Success events for the Audit User Account Management subcategory
Select the Account Management policy and enable Success events for the Audit Security Group Management subcategory.
Select DS Access. The value of Directory Service Access should be set to Success.
Comments
0 comments
Please sign in to leave a comment.