Forum Discussion
Przem0
Mar 09, 2023Brass Contributor
Configuration of ID 4662 makes ID 4780?
Hi,
Does configuration of object auditing for event ID https://learn.microsoft.com/en-us/defender-for-identity/configure-windows-event-collection#configure-object-auditing could trigger event ID https://learn.microsoft.com/en-us/windows/security/threat-protection/auditing/event-4780?
As we had health alert about misconfiguration of DS Object Auditing we followed documentation and alert was auto closed. Then we received alert - The ACL was set on accounts which are members of administrators groups - in another monitoring tool.
Looking forward any feedback.
Regards,
Przem0
1 Reply
- thalpiusBrass ContributorCould be, but if you don't see it again after configuring the audit, I wouldn't bother with it too much.