This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

AD Advanced Audit Configuration

We're consolidating 2 Windows 2012 R2 forests into another 2012 R2 forest and the new audit settings for 2012 R2 are getting in the way. With the introduction of server 2008 we got the new Advanced Audit Configuration (Computer Configuration -> Windows Settings -> Security Settings -> Advanced Audit Policy Configuration -> Audit Policies) which can be configured to override the older category settings. It took a great deal of fine-tuning Advanced Audit Policy settings to get QMM to recognize that auditing was turned in the target. Now I'm struggling to get this to work for the source domains. The QMM documentation does not address the advanced audit policy config, which is something these domains need to have enabled. Despite all settings being enabled for success / fail for account management and DS access, the DSA log stills says auditing needs to be enabled on the source domains. But if we run audit pol or RSOP, the settings are clearly enabled. Has anyone else run into this issue?

Parents
  • Hi DJ - I have a few questions to get more background on your situation.

    1.) What exact error is specified in the DSA.log?
    2.) For the account synchronizing from the source domain in the DSA settings, does that account have DA rights, or more granular restrictive rights as outlined in the QMM access rights/setup doc?
    3.) Are you merging/replacing the security descriptor as a part of your DSA/Migration sessions?
Reply
  • Hi DJ - I have a few questions to get more background on your situation.

    1.) What exact error is specified in the DSA.log?
    2.) For the account synchronizing from the source domain in the DSA settings, does that account have DA rights, or more granular restrictive rights as outlined in the QMM access rights/setup doc?
    3.) Are you merging/replacing the security descriptor as a part of your DSA/Migration sessions?
Children
No Data