Jan 20 2023 08:21 AM
I have received this alert recently and have tried everything to enable auditing per the recommendation found here Configure Windows Event collection - Microsoft Defender for Identity | Microsoft Learn
The errors are getting in the security logs, but MS Defender for Identity continues to say there is a health issue.
Any ideas?
Jan 21 2023 10:59 AM
It might be related to a bug we've seen in non-English operating systems.
Could this be the case in your environment as well?
Jan 23 2023 05:21 AM
Jan 24 2023 12:40 AM
Jan 26 2023 02:23 AM
The bug (not 100% sure yet) is that the health alert is firing on non-English operating systems (e.g. German) even when the auditing configuration is Ok.
Are your servers configured with a non EN locale?
Jan 27 2023 11:28 AM
They are not, they are configured for US.
Jan 31 2023 01:07 AM
Mar 07 2023 06:21 AM
@Martin_Schvartzmanis this bug also potentially related to the message, Directory Services Object Auditing is not configured as required? We are seeing both of these in our environment despite having configured the policy per the documentation. Thanks!
Mar 13 2023 02:40 AM
Mar 22 2023 01:43 PM
@Arngrimur Magnusson @MichaelDow @MeatHeadPro
We found a couple of bugs in the detection logic for this health alert.
One (as mentioned above) for non-English operating systems, and another for domain schemas earlier than 87.
These are fixed as part of v2.201 that should be rolled out starting next week.
Mar 28 2023 04:32 AM
I apologize, the fix (non-English operating systems, and schemas earlier than 87) in v2.201 is for the Directory Services Object Auditing health alert, and not for the Directory Services Advanced Auditing health alert as you initially reported.
Could you please open a support ticket and share more details on the problem you are facing?
Apr 11 2023 02:59 AM - edited Apr 11 2023 03:01 AM
Hello @Martin_Schvartzman!
Since activating these rules we're seeing 20GB/Logfiles per DC-server, why? It's an insane amount of data.
Apr 12 2023 11:48 PM
I updated the script. Please let me know if the issue persists.
Apr 12 2023 11:54 PM
The auditing configuration we require shouldn't be causing that.
Please make sure you followed the documentation to enable only the required auditing settings and didn't select all categories for success and failure for the Advanced Auditing nor all the object types and all permissions (List contents, Read all properties and Read permissions should be unchecked) in Object Auditing.
Apr 17 2023 08:41 AM
Jun 21 2023 07:17 AM
Jul 12 2023 04:34 AM
@terryhugill can you share solution?
Sep 08 2023 05:25 AM
@Arngrimur Magnussoncould you elaborate on the solution please?