This guide explains how to configure a domain and its associated domain controllers in ADAudit Plus to enable real-time auditing of Active Directory changes and logon activities.
Before configuring domains and domain controllers, ensure the following requirements are met.
ADAudit Plus is installed and running on a supported Windows server.
The server is part of the Active Directory domain you intend to audit.
The service account used has the necessary permissions and privileges, including membership in the domain admins group (or delegated permissions as per the least privilege model) and the event log readers group.
Required ports are open for WMI, Server Message Block, and RPC communication between ADAudit Plus and the domain controllers.
Audit policies are enabled across all domain controllers.
Go to Domain Settings. Click Add Domain to begin configuration.
Select Click here to discover Domain Controllers
The NetBIOS name will be auto-fetched or can be entered manually.
If ADAudit Plus is unable to fetch the name of the available domain controllers enter the hostname or IP address of the domain controller for this domain.
Click Save to add the domain and domain controller in ADAudit Plus.
Enter the domain user account credentials that have sufficient privileges, preferably a domain admin account or a service account with the least required privilege. More info can be found here.
Click OK to verify the successful authentication and to save the settings.
Click Add Domain Controller to add a domain controller after configuration.
Click Audit Policy: Configure to have the required audit policies enabled for auditing. More info can be found here.
You can also check the Status of the configured Domain controller in the Domain Settings page to confirm that audit data is being successfully collected.
Use a dedicated service account with only the required permissions.
Apply audit policies using a GPO at the default domain controller policy.
Ensure system clocks are synchronized between ADAudit Plus and all domain controllers.
Regularly verify connectivity and the credentials of configured domains.
Configure real-time alerts for critical changes via the configuration > alerts section.