SIEM, Vulnerability Scanning, Server Monitoring and Compliance Training for IT Professionals
Table of Contents

Windows Audit Policy Monitor Template

The Windows Audit Policy Monitor Template enables Network Administrators to capture the Windows Audit Policy of any target host then using the captured policy, apply the Windows Audit Policy to any machine as well as continually verify the Windows Audit Policy has not been modified. This template is typically used to enable Network Administrators to apply Windows Audit Policies to off-domain hosts, hosts that reside in a DMZ as well as verify all hosts that reside in a domain have the correct Windows Audit Policy applied.

In this Topic

Video Tutorial

How to Monitor and Enforce Windows Audit Policies

To Create the Windows Audit Policy Monitor Template

  • From the Menu Bar, select File | New. The Create New Object View displays.
  • From the Create New Object View, expand Templates | Windows Monitors then select Windows Audit Policy Monitor. The New Template Properties View displays.
  • The Template Properties view contains 4 tabs.

Options Configuration

  • Use the Windows server or workstation drop-down to select the target host you would like to use as a baseline while configuring this Template.
Select Host Control
Select Host Drop-Down
Note
Once selected, the server is automatically assigned to this template and the Audit Policy Table populated with the current Windows Audit Policy.
  • Use the Enforce baseline audit policy checkbox to apply the configured audit policy to each assigned host.
  • Use the Audit Policy Data Table to configure the baseline policy to verify and optionally apply to each assigned host.
Windows Audit Policy Monitor and Enforcement Properties View
Windows Audit Policy Monitor and Enforcement Properties View

Related Topics

Template Properties

Windows Templates