[Forgot Password]
Login  Register Subscribe

24128

 
 

131573

 
 

110139

 
 

909

 
 

85964

 
 

136

Paid content will be excluded from the download.


Download | Alert*
OVAL

Audit Policy: DS Access: Detailed Directory Service Replication

ID: oval:org.secpod.oval:def:22760Date: (C)2015-01-07   (M)2018-03-24
Class: COMPLIANCEFamily: windows




This subcategory reports detailed information about the information replicating between domain controllers. These events can be very high in volume. Events for this subcategory include: ? 4928: An Active Directory replica source naming context was established. ? 4929 : An Active Directory replica source naming context was removed. ? 4930 : An Active Directory replica source naming context was modified. ? 4931 : An Active Directory replica destination naming context was modified. ? 4934 : Attributes of an Active Directory object were replicated. ? 4935 : Replication failure begins. ? 4936 : Replication failure ends. ? 4937 : A lingering object was removed from a replica. Refer to the Microsoft Knowledgebase article ?Description of security events in Windows Vista and in Windows Server 2008? for the most recent information about this setting: http://support.microsoft.com/default.aspx/kb/947226. This policy setting in the DS Access audit category enables domain controllers to report detailed information about information that replicates between domain controllers. Fix: (1) GPO: Computer Configuration\Windows Settings\Security Settings\Advanced Audit Policy Configuration\Audit Policies\DS Access!Audit Policy: DS Access: Detailed Directory Service Replication (2) REG: NO REGISTRY INFO

Platform:
Microsoft Windows Server 2012 R2
Reference:
CCE-37361-3
CPE    1
cpe:/o:microsoft:windows_server_2012::r2:x64
CCE    1
CCE-37361-3

© SecPod Technologies