Audit Policy: Audit account managementID: oval:org.secpod.oval:def:18762 | Date: (C)2014-05-29 (M)2021-06-02 |
Class: COMPLIANCE | Family: windows |
Auditing of Audit account management events on success should be enabled or disabled as appropriate.
This security setting determines whether to audit each event of account management on a computer. Examples of account management events include: * A user account or group is created, changed, or deleted. * A user account is renamed, disabled, or enabled. * A password is set or changed. If you define this policy setting, you can specify whether to audit successes, audit failures, or not audit the event type at all. Success audits generate an audit entry when any account management event succeeds. Failure audits generate an audit entry when any account management event fails.
Fix:
(1) GPO: Computer Configuration\Windows Settings\Security Settings\Local Policies\Audit Policy\Audit account management
(2) REG: NO INFO
Platform: |
Microsoft Windows Server 2008 R2 |