Group Policy paths¶
Where each kit setting lives in a Group Policy Object, for domain
administrators building the GPO by hand in the Group Policy Management
Editor. Every path below is under Computer Configuration > Policies.
The GPO pack
(fleet\New-GpoPack.ps1) generates the same audit policy and registry
values as files, for LGPO or as a reference. Intune instead? See
Settings catalog.
Things to know before you start:
- Include "Audit: Force audit policy subcategory settings (Windows
Vista or later) to override audit policy category settings" (the
ForceSubcategoryAuditrow) in the same GPO, so basic audit policy can't override the advanced settings below (Microsoft's guidance). - Rows marked (DC) belong in a GPO linked to the Domain Controllers OU. They are busy there: read the DC notes first.
- PowerShell 7 rows need PowerShell 7's own administrative template
in the domain's
central store:
copy
PowerShellCoreExecutionPolicy.admxfrom the PowerShell 7 folder intoPolicyDefinitionsunder SYSVOL, and its.admlinto the matching language folder (en-US). TheInstallPSCorePolicyDefinitions.ps1that ships with PowerShell 7 installs them on the local machine only. - SMB auditing needs Windows 11 24H2 or Windows Server 2025; older versions ignore those settings.
- Leave "Control Event Log behavior when the log file reaches its maximum size" Disabled or Not configured (Event Log Service > each classic log). Enabled means "do not overwrite": logging stops when the log fills. Test fails it, and Enable won't override Group Policy.
- Only the classic logs have a size template. The other kit logs are
in the second table: size them with a computer startup script, or run
Enable-LoggingBaseline.ps1on the host. - Mind the Tier column. Leave HighVolume rows out unless you apply that tier (see Baselines).
- Check the result on a host with
Test-LoggingBaseline.ps1: it reads the effective policy, whatever delivered it.
Settings with a Group Policy path¶
| Setting | Type | Tier | Path (under Computer Configuration > Policies) | Value |
|---|---|---|---|---|
| Credential Validation | Audit | Core | Windows Settings > Security Settings > Advanced Audit Policy Configuration > Audit Policies > Account Logon > Audit Credential Validation | Success and Failure |
| Kerberos Authentication Service (DC) | Audit | Core | Windows Settings > Security Settings > Advanced Audit Policy Configuration > Audit Policies > Account Logon > Audit Kerberos Authentication Service | Success and Failure |
| Kerberos Service Ticket Operations (DC) | Audit | Core | Windows Settings > Security Settings > Advanced Audit Policy Configuration > Audit Policies > Account Logon > Audit Kerberos Service Ticket Operations | Success and Failure |
| Computer Account Management (DC) | Audit | Core | Windows Settings > Security Settings > Advanced Audit Policy Configuration > Audit Policies > Account Management > Audit Computer Account Management | Success and Failure |
| Distribution Group Management (DC) | Audit | Core | Windows Settings > Security Settings > Advanced Audit Policy Configuration > Audit Policies > Account Management > Audit Distribution Group Management | Success and Failure |
| Other Account Management Events | Audit | Core | Windows Settings > Security Settings > Advanced Audit Policy Configuration > Audit Policies > Account Management > Audit Other Account Management Events | Success and Failure |
| Security Group Management | Audit | Core | Windows Settings > Security Settings > Advanced Audit Policy Configuration > Audit Policies > Account Management > Audit Security Group Management | Success and Failure |
| User Account Management | Audit | Core | Windows Settings > Security Settings > Advanced Audit Policy Configuration > Audit Policies > Account Management > Audit User Account Management | Success and Failure |
| Plug and Play | Audit | Core | Windows Settings > Security Settings > Advanced Audit Policy Configuration > Audit Policies > Detailed Tracking > Audit PNP Activity | Success and Failure |
| Process Creation | Audit | HighVolume | Windows Settings > Security Settings > Advanced Audit Policy Configuration > Audit Policies > Detailed Tracking > Audit Process Creation | Success and Failure |
| RPC Events | Audit | Core | Windows Settings > Security Settings > Advanced Audit Policy Configuration > Audit Policies > Detailed Tracking > Audit RPC Events | Success and Failure |
| Directory Service Access (DC) | Audit | Core | Windows Settings > Security Settings > Advanced Audit Policy Configuration > Audit Policies > DS Access > Audit Directory Service Access | Success and Failure |
| Directory Service Changes (DC) | Audit | Core | Windows Settings > Security Settings > Advanced Audit Policy Configuration > Audit Policies > DS Access > Audit Directory Service Changes | Success and Failure |
| Account Lockout | Audit | Core | Windows Settings > Security Settings > Advanced Audit Policy Configuration > Audit Policies > Logon/Logoff > Audit Account Lockout | Success and Failure |
| Logoff | Audit | Core | Windows Settings > Security Settings > Advanced Audit Policy Configuration > Audit Policies > Logon/Logoff > Audit Logoff | Success and Failure |
| Logon | Audit | Core | Windows Settings > Security Settings > Advanced Audit Policy Configuration > Audit Policies > Logon/Logoff > Audit Logon | Success and Failure |
| Other Logon/Logoff Events | Audit | Core | Windows Settings > Security Settings > Advanced Audit Policy Configuration > Audit Policies > Logon/Logoff > Audit Other Logon Logoff Events | Success and Failure |
| Special Logon | Audit | Core | Windows Settings > Security Settings > Advanced Audit Policy Configuration > Audit Policies > Logon/Logoff > Audit Special Logon | Success and Failure |
| Certification Services | Audit | Core | Windows Settings > Security Settings > Advanced Audit Policy Configuration > Audit Policies > Object Access > Audit Certification Services | Success and Failure |
| File Share | Audit | Core | Windows Settings > Security Settings > Advanced Audit Policy Configuration > Audit Policies > Object Access > Audit File Share | Success and Failure |
| Filtering Platform Connection | Audit | HighVolume | Windows Settings > Security Settings > Advanced Audit Policy Configuration > Audit Policies > Object Access > Audit Filtering Platform Connection | Success and Failure |
| Other Object Access Events | Audit | Core | Windows Settings > Security Settings > Advanced Audit Policy Configuration > Audit Policies > Object Access > Audit Other Object Access Events | Success and Failure |
| Removable Storage | Audit | Core | Windows Settings > Security Settings > Advanced Audit Policy Configuration > Audit Policies > Object Access > Audit Removable Storage | Success and Failure |
| SAM | Audit | Core | Windows Settings > Security Settings > Advanced Audit Policy Configuration > Audit Policies > Object Access > Audit SAM | Success and Failure |
| Audit Policy Change | Audit | Core | Windows Settings > Security Settings > Advanced Audit Policy Configuration > Audit Policies > Policy Change > Audit Policy Change | Success and Failure |
| Authentication Policy Change | Audit | Core | Windows Settings > Security Settings > Advanced Audit Policy Configuration > Audit Policies > Policy Change > Audit Authentication Policy Change | Success and Failure |
| Other Policy Change Events | Audit | Core | Windows Settings > Security Settings > Advanced Audit Policy Configuration > Audit Policies > Policy Change > Audit Other Policy Change Events | Success and Failure |
| Sensitive Privilege Use | Audit | HighVolume | Windows Settings > Security Settings > Advanced Audit Policy Configuration > Audit Policies > Privilege Use > Audit Sensitive Privilege Use | Success and Failure |
| IPsec Driver | Audit | HighVolume | Windows Settings > Security Settings > Advanced Audit Policy Configuration > Audit Policies > System > Audit IPsec Driver | Success and Failure |
| Security State Change | Audit | Core | Windows Settings > Security Settings > Advanced Audit Policy Configuration > Audit Policies > System > Audit Security State Change | Success and Failure |
| Security System Extension | Audit | Core | Windows Settings > Security Settings > Advanced Audit Policy Configuration > Audit Policies > System > Audit Security System Extension | Success and Failure |
| System Integrity | Audit | Core | Windows Settings > Security Settings > Advanced Audit Policy Configuration > Audit Policies > System > Audit System Integrity | Success and Failure |
| Other System Events | Audit | Core | Windows Settings > Security Settings > Advanced Audit Policy Configuration > Audit Policies > System > Audit Other System Events | Failure |
| CmdLineAudit | Registry | HighVolume | Administrative Templates > System > Audit Process Creation > Include command line in process creation events | Enabled |
| ScriptBlock64 | Registry | HighVolume | Administrative Templates > Windows Components > Windows PowerShell > Turn on PowerShell Script Block Logging | Enabled |
| ModuleLogging64 | Registry | HighVolume | Administrative Templates > Windows Components > Windows PowerShell > Turn on Module Logging | Enabled |
| ModuleNames64 | Registry | HighVolume | Administrative Templates > Windows Components > Windows PowerShell > Turn on Module Logging | Module Names (Show...): * |
| PS7ScriptBlock64 | Registry | HighVolume | Administrative Templates > PowerShell Core > Turn on PowerShell Script Block Logging | Enabled, with "Use Windows PowerShell Policy setting." ticked. Needs PowerShell 7's own template in the central store (see the note above). |
| PS7ModuleLogging64 | Registry | HighVolume | Administrative Templates > PowerShell Core > Turn on Module Logging | Enabled, with "Use Windows PowerShell Policy setting." ticked. Needs PowerShell 7's own template in the central store (see the note above). |
| NtlmOutboundAudit | Registry | Core | Windows Settings > Security Settings > Local Policies > Security Options > Network security: Restrict NTLM: Outgoing NTLM traffic to remote servers | Audit all |
| NtlmInboundAudit | Registry | Core | Windows Settings > Security Settings > Local Policies > Security Options > Network security: Restrict NTLM: Audit Incoming NTLM Traffic | Enable auditing for all accounts |
| NtlmDomainAudit (DC) | Registry | Core | Windows Settings > Security Settings > Local Policies > Security Options > Network security: Restrict NTLM: Audit NTLM authentication in this domain | Enable all |
| ForceSubcategoryAudit | Registry | Core | Windows Settings > Security Settings > Local Policies > Security Options > Audit: Force audit policy subcategory settings (Windows Vista or later) to override audit policy category settings | Enabled |
| AuditClientDoesNotSupportEncryption | SMB audit | Core | Administrative Templates > Network > Lanman Server > Audit client does not support encryption | Enabled |
| AuditClientDoesNotSupportSigning | SMB audit | Core | Administrative Templates > Network > Lanman Server > Audit client does not support signing | Enabled |
| AuditServerDoesNotSupportEncryption | SMB audit | Core | Administrative Templates > Network > Lanman Workstation > Audit server does not support encryption | Enabled |
| AuditServerDoesNotSupportSigning | SMB audit | Core | Administrative Templates > Network > Lanman Workstation > Audit server does not support signing | Enabled |
| AuditInsecureGuestLogon | SMB audit | Core | Administrative Templates > Network > Lanman Workstation > Audit insecure guest logon | Enabled |
| ServerAuditInsecureGuestLogon | SMB audit | Core | Administrative Templates > Network > Lanman Server > Audit insecure guest logon | Enabled |
| Security | Log size | Core | Administrative Templates > Windows Components > Event Log Service > Security > Specify the maximum log file size (KB) | Enabled, 1048576 KB |
| System | Log size | Core | Administrative Templates > Windows Components > Event Log Service > System > Specify the maximum log file size (KB) | Enabled, 131072 KB |
| Application | Log size | Core | Administrative Templates > Windows Components > Event Log Service > Application > Specify the maximum log file size (KB) | Enabled, 131072 KB |
Settings without a Group Policy template¶
| Setting | Type | Why |
|---|---|---|
| ScriptBlock32 | Registry | No Administrative Template writes the 32-bit (WOW64) copy. Use Group Policy Preferences > Windows Settings > Registry, or LGPO with the GPO pack's registry.txt. |
| ModuleLogging32 | Registry | No Administrative Template writes the 32-bit (WOW64) copy. Use Group Policy Preferences > Windows Settings > Registry, or LGPO with the GPO pack's registry.txt. |
| ModuleNames32 | Registry | No Administrative Template writes the 32-bit (WOW64) copy. Use Group Policy Preferences > Windows Settings > Registry, or LGPO with the GPO pack's registry.txt. |
| PS7ScriptBlock32 | Registry | No Administrative Template writes the 32-bit (WOW64) copy. Use Group Policy Preferences > Windows Settings > Registry, or LGPO with the GPO pack's registry.txt. |
| PS7ModuleLogging32 | Registry | No Administrative Template writes the 32-bit (WOW64) copy. Use Group Policy Preferences > Windows Settings > Registry, or LGPO with the GPO pack's registry.txt. |
| Microsoft-Windows-PowerShell/Operational | Log | No Group Policy template for this log's size. |
| Windows PowerShell | Log | No Group Policy template for this log's size. |
| PowerShellCore/Operational | Log | No Group Policy template for this log's size or enablement. |
| Microsoft-Windows-Windows Defender/Operational | Log | No Group Policy template for this log's size. |
| Microsoft-Windows-Bits-Client/Operational | Log | No Group Policy template for this log's size. |
| Microsoft-Windows-Windows Firewall With Advanced Security/Firewall | Log | No Group Policy template for this log's size. |
| Microsoft-Windows-NTLM/Operational | Log | No Group Policy template for this log's size. |
| Microsoft-Windows-Security-Mitigations/KernelMode | Log | No Group Policy template for this log's size. |
| Microsoft-Windows-Security-Mitigations/UserMode | Log | No Group Policy template for this log's size. |
| Microsoft-Windows-PrintService/Admin | Log | No Group Policy template for this log's size. |
| Microsoft-Windows-PrintService/Operational | Log | No Group Policy template for this log's size or enablement. |
| Microsoft-Windows-SmbClient/Security | Log | No Group Policy template for this log's size. |
| Microsoft-Windows-AppLocker/EXE and DLL | Log | No Group Policy template for this log's size. |
| Microsoft-Windows-AppLocker/MSI and Script | Log | No Group Policy template for this log's size. |
| Microsoft-Windows-AppLocker/Packaged app-Deployment | Log | No Group Policy template for this log's size. |
| Microsoft-Windows-AppLocker/Packaged app-Execution | Log | No Group Policy template for this log's size. |
| Microsoft-Windows-CodeIntegrity/Operational | Log | No Group Policy template for this log's size. |
| Microsoft-Windows-Diagnosis-Scripted/Operational | Log | No Group Policy template for this log's size. |
| Microsoft-Windows-DriverFrameworks-UserMode/Operational | Log | No Group Policy template for this log's size or enablement. |
| Microsoft-Windows-WMI-Activity/Operational | Log | No Group Policy template for this log's size. |
| Microsoft-Windows-TerminalServices-LocalSessionManager/Operational | Log | No Group Policy template for this log's size. |
| Microsoft-Windows-TerminalServices-RemoteConnectionManager/Operational | Log | No Group Policy template for this log's size or enablement. |
| Microsoft-Windows-RemoteDesktopServices-RdpCoreTS/Operational | Log | No Group Policy template for this log's size or enablement. |
| Microsoft-Windows-TaskScheduler/Operational | Log | No Group Policy template for this log's size or enablement. |
| Microsoft-Windows-SMBServer/Audit | Log | No Group Policy template for this log's size. |
| Microsoft-Windows-SmbClient/Audit | Log | No Group Policy template for this log's size. |
| Microsoft-Windows-SMBServer/Security | Log | No Group Policy template for this log's size or enablement. |
| Microsoft-Windows-SMBServer/Operational | Log | No Group Policy template for this log's size or enablement. |
| Microsoft-Windows-Crypto-DPAPI/Debug | Log | No Group Policy template for this log's size or enablement. |
| AdcsAuditFilter | Registry | No Group Policy template, and it needs a CertSvc restart: set it on the CA in a change window (Enable-LoggingBaseline.ps1 there). |