SIEM, Vulnerability Scanning, Server Monitoring and Compliance Training for IT Professionals
Table of Contents

Windows Audit Policy Monitor Template

The Windows Audit Policy Monitor Template enables users to capture the Windows Audit Policy of any target host then using the captured policy, apply the Windows Audit Policy to any machine as well as continually verify the Windows Audit Policy has not been modified. This template is typically used to enable network administrators to apply Windows Audit Policies to off-domain hosts, hosts that reside in a DMZ as well as verify all hosts that reside in a domain have the correct Windows Audit Policy applied.

Tutorials

How to Monitor and Enforce Windows Audit Policies

How to configure the Windows Audit Policy Monitor Template:

  • From the Menu Bar, select File | New. The Create New Object View displays.
  • From the Create New Object View, expand Templates | Windows Monitors then select Windows Audit Policy Monitor. The New Template Properties View displays.
  • The Template Properties view contains 4 tabs.

The Options Tab

  • Use the Windows server and workstation drop-down to select the target host you would like to use as a baseline.
Note
Once selected, the server is automatically assigned to this template and the Audit Policy Table populated with the current Windows Audit Policy.
  • Use the Enforce baseline audit policy checkbox to configure the template to apply the baseline policy to each assigned host.
  • Use the Audit Policy Data Table to configure the baseline policy to verify and optionally apply to each assigned host.
Windows Audit Policy Monitor and Enforcement Properties View
Windows Audit Policy Monitor and Enforcement Properties View

Related Topics

Template Properties

Windows Templates