Skip to content

Group Policy paths

Where each kit setting lives in a Group Policy Object, for domain administrators building the GPO by hand in the Group Policy Management Editor. Every path below is under Computer Configuration > Policies. The GPO pack (fleet\New-GpoPack.ps1) generates the same audit policy and registry values as files, for LGPO or as a reference. Intune instead? See Settings catalog.

Things to know before you start:

  • Include "Audit: Force audit policy subcategory settings (Windows Vista or later) to override audit policy category settings" (the ForceSubcategoryAudit row) in the same GPO, so basic audit policy can't override the advanced settings below (Microsoft's guidance).
  • Rows marked (DC) belong in a GPO linked to the Domain Controllers OU. They are busy there: read the DC notes first.
  • PowerShell 7 rows need PowerShell 7's own administrative template in the domain's central store: copy PowerShellCoreExecutionPolicy.admx from the PowerShell 7 folder into PolicyDefinitions under SYSVOL, and its .adml into the matching language folder (en-US). The InstallPSCorePolicyDefinitions.ps1 that ships with PowerShell 7 installs them on the local machine only.
  • SMB auditing needs Windows 11 24H2 or Windows Server 2025; older versions ignore those settings.
  • Leave "Control Event Log behavior when the log file reaches its maximum size" Disabled or Not configured (Event Log Service > each classic log). Enabled means "do not overwrite": logging stops when the log fills. Test fails it, and Enable won't override Group Policy.
  • Only the classic logs have a size template. The other kit logs are in the second table: size them with a computer startup script, or run Enable-LoggingBaseline.ps1 on the host.
  • Mind the Tier column. Leave HighVolume rows out unless you apply that tier (see Baselines).
  • Check the result on a host with Test-LoggingBaseline.ps1: it reads the effective policy, whatever delivered it.

Settings with a Group Policy path

Setting Type Tier Path (under Computer Configuration > Policies) Value
Credential Validation Audit Core Windows Settings > Security Settings > Advanced Audit Policy Configuration > Audit Policies > Account Logon > Audit Credential Validation Success and Failure
Kerberos Authentication Service (DC) Audit Core Windows Settings > Security Settings > Advanced Audit Policy Configuration > Audit Policies > Account Logon > Audit Kerberos Authentication Service Success and Failure
Kerberos Service Ticket Operations (DC) Audit Core Windows Settings > Security Settings > Advanced Audit Policy Configuration > Audit Policies > Account Logon > Audit Kerberos Service Ticket Operations Success and Failure
Computer Account Management (DC) Audit Core Windows Settings > Security Settings > Advanced Audit Policy Configuration > Audit Policies > Account Management > Audit Computer Account Management Success and Failure
Distribution Group Management (DC) Audit Core Windows Settings > Security Settings > Advanced Audit Policy Configuration > Audit Policies > Account Management > Audit Distribution Group Management Success and Failure
Other Account Management Events Audit Core Windows Settings > Security Settings > Advanced Audit Policy Configuration > Audit Policies > Account Management > Audit Other Account Management Events Success and Failure
Security Group Management Audit Core Windows Settings > Security Settings > Advanced Audit Policy Configuration > Audit Policies > Account Management > Audit Security Group Management Success and Failure
User Account Management Audit Core Windows Settings > Security Settings > Advanced Audit Policy Configuration > Audit Policies > Account Management > Audit User Account Management Success and Failure
Plug and Play Audit Core Windows Settings > Security Settings > Advanced Audit Policy Configuration > Audit Policies > Detailed Tracking > Audit PNP Activity Success and Failure
Process Creation Audit HighVolume Windows Settings > Security Settings > Advanced Audit Policy Configuration > Audit Policies > Detailed Tracking > Audit Process Creation Success and Failure
RPC Events Audit Core Windows Settings > Security Settings > Advanced Audit Policy Configuration > Audit Policies > Detailed Tracking > Audit RPC Events Success and Failure
Directory Service Access (DC) Audit Core Windows Settings > Security Settings > Advanced Audit Policy Configuration > Audit Policies > DS Access > Audit Directory Service Access Success and Failure
Directory Service Changes (DC) Audit Core Windows Settings > Security Settings > Advanced Audit Policy Configuration > Audit Policies > DS Access > Audit Directory Service Changes Success and Failure
Account Lockout Audit Core Windows Settings > Security Settings > Advanced Audit Policy Configuration > Audit Policies > Logon/Logoff > Audit Account Lockout Success and Failure
Logoff Audit Core Windows Settings > Security Settings > Advanced Audit Policy Configuration > Audit Policies > Logon/Logoff > Audit Logoff Success and Failure
Logon Audit Core Windows Settings > Security Settings > Advanced Audit Policy Configuration > Audit Policies > Logon/Logoff > Audit Logon Success and Failure
Other Logon/Logoff Events Audit Core Windows Settings > Security Settings > Advanced Audit Policy Configuration > Audit Policies > Logon/Logoff > Audit Other Logon Logoff Events Success and Failure
Special Logon Audit Core Windows Settings > Security Settings > Advanced Audit Policy Configuration > Audit Policies > Logon/Logoff > Audit Special Logon Success and Failure
Certification Services Audit Core Windows Settings > Security Settings > Advanced Audit Policy Configuration > Audit Policies > Object Access > Audit Certification Services Success and Failure
File Share Audit Core Windows Settings > Security Settings > Advanced Audit Policy Configuration > Audit Policies > Object Access > Audit File Share Success and Failure
Filtering Platform Connection Audit HighVolume Windows Settings > Security Settings > Advanced Audit Policy Configuration > Audit Policies > Object Access > Audit Filtering Platform Connection Success and Failure
Other Object Access Events Audit Core Windows Settings > Security Settings > Advanced Audit Policy Configuration > Audit Policies > Object Access > Audit Other Object Access Events Success and Failure
Removable Storage Audit Core Windows Settings > Security Settings > Advanced Audit Policy Configuration > Audit Policies > Object Access > Audit Removable Storage Success and Failure
SAM Audit Core Windows Settings > Security Settings > Advanced Audit Policy Configuration > Audit Policies > Object Access > Audit SAM Success and Failure
Audit Policy Change Audit Core Windows Settings > Security Settings > Advanced Audit Policy Configuration > Audit Policies > Policy Change > Audit Policy Change Success and Failure
Authentication Policy Change Audit Core Windows Settings > Security Settings > Advanced Audit Policy Configuration > Audit Policies > Policy Change > Audit Authentication Policy Change Success and Failure
Other Policy Change Events Audit Core Windows Settings > Security Settings > Advanced Audit Policy Configuration > Audit Policies > Policy Change > Audit Other Policy Change Events Success and Failure
Sensitive Privilege Use Audit HighVolume Windows Settings > Security Settings > Advanced Audit Policy Configuration > Audit Policies > Privilege Use > Audit Sensitive Privilege Use Success and Failure
IPsec Driver Audit HighVolume Windows Settings > Security Settings > Advanced Audit Policy Configuration > Audit Policies > System > Audit IPsec Driver Success and Failure
Security State Change Audit Core Windows Settings > Security Settings > Advanced Audit Policy Configuration > Audit Policies > System > Audit Security State Change Success and Failure
Security System Extension Audit Core Windows Settings > Security Settings > Advanced Audit Policy Configuration > Audit Policies > System > Audit Security System Extension Success and Failure
System Integrity Audit Core Windows Settings > Security Settings > Advanced Audit Policy Configuration > Audit Policies > System > Audit System Integrity Success and Failure
Other System Events Audit Core Windows Settings > Security Settings > Advanced Audit Policy Configuration > Audit Policies > System > Audit Other System Events Failure
CmdLineAudit Registry HighVolume Administrative Templates > System > Audit Process Creation > Include command line in process creation events Enabled
ScriptBlock64 Registry HighVolume Administrative Templates > Windows Components > Windows PowerShell > Turn on PowerShell Script Block Logging Enabled
ModuleLogging64 Registry HighVolume Administrative Templates > Windows Components > Windows PowerShell > Turn on Module Logging Enabled
ModuleNames64 Registry HighVolume Administrative Templates > Windows Components > Windows PowerShell > Turn on Module Logging Module Names (Show...): *
PS7ScriptBlock64 Registry HighVolume Administrative Templates > PowerShell Core > Turn on PowerShell Script Block Logging Enabled, with "Use Windows PowerShell Policy setting." ticked. Needs PowerShell 7's own template in the central store (see the note above).
PS7ModuleLogging64 Registry HighVolume Administrative Templates > PowerShell Core > Turn on Module Logging Enabled, with "Use Windows PowerShell Policy setting." ticked. Needs PowerShell 7's own template in the central store (see the note above).
NtlmOutboundAudit Registry Core Windows Settings > Security Settings > Local Policies > Security Options > Network security: Restrict NTLM: Outgoing NTLM traffic to remote servers Audit all
NtlmInboundAudit Registry Core Windows Settings > Security Settings > Local Policies > Security Options > Network security: Restrict NTLM: Audit Incoming NTLM Traffic Enable auditing for all accounts
NtlmDomainAudit (DC) Registry Core Windows Settings > Security Settings > Local Policies > Security Options > Network security: Restrict NTLM: Audit NTLM authentication in this domain Enable all
ForceSubcategoryAudit Registry Core Windows Settings > Security Settings > Local Policies > Security Options > Audit: Force audit policy subcategory settings (Windows Vista or later) to override audit policy category settings Enabled
AuditClientDoesNotSupportEncryption SMB audit Core Administrative Templates > Network > Lanman Server > Audit client does not support encryption Enabled
AuditClientDoesNotSupportSigning SMB audit Core Administrative Templates > Network > Lanman Server > Audit client does not support signing Enabled
AuditServerDoesNotSupportEncryption SMB audit Core Administrative Templates > Network > Lanman Workstation > Audit server does not support encryption Enabled
AuditServerDoesNotSupportSigning SMB audit Core Administrative Templates > Network > Lanman Workstation > Audit server does not support signing Enabled
AuditInsecureGuestLogon SMB audit Core Administrative Templates > Network > Lanman Workstation > Audit insecure guest logon Enabled
ServerAuditInsecureGuestLogon SMB audit Core Administrative Templates > Network > Lanman Server > Audit insecure guest logon Enabled
Security Log size Core Administrative Templates > Windows Components > Event Log Service > Security > Specify the maximum log file size (KB) Enabled, 1048576 KB
System Log size Core Administrative Templates > Windows Components > Event Log Service > System > Specify the maximum log file size (KB) Enabled, 131072 KB
Application Log size Core Administrative Templates > Windows Components > Event Log Service > Application > Specify the maximum log file size (KB) Enabled, 131072 KB

Settings without a Group Policy template

Setting Type Why
ScriptBlock32 Registry No Administrative Template writes the 32-bit (WOW64) copy. Use Group Policy Preferences > Windows Settings > Registry, or LGPO with the GPO pack's registry.txt.
ModuleLogging32 Registry No Administrative Template writes the 32-bit (WOW64) copy. Use Group Policy Preferences > Windows Settings > Registry, or LGPO with the GPO pack's registry.txt.
ModuleNames32 Registry No Administrative Template writes the 32-bit (WOW64) copy. Use Group Policy Preferences > Windows Settings > Registry, or LGPO with the GPO pack's registry.txt.
PS7ScriptBlock32 Registry No Administrative Template writes the 32-bit (WOW64) copy. Use Group Policy Preferences > Windows Settings > Registry, or LGPO with the GPO pack's registry.txt.
PS7ModuleLogging32 Registry No Administrative Template writes the 32-bit (WOW64) copy. Use Group Policy Preferences > Windows Settings > Registry, or LGPO with the GPO pack's registry.txt.
Microsoft-Windows-PowerShell/Operational Log No Group Policy template for this log's size.
Windows PowerShell Log No Group Policy template for this log's size.
PowerShellCore/Operational Log No Group Policy template for this log's size or enablement.
Microsoft-Windows-Windows Defender/Operational Log No Group Policy template for this log's size.
Microsoft-Windows-Bits-Client/Operational Log No Group Policy template for this log's size.
Microsoft-Windows-Windows Firewall With Advanced Security/Firewall Log No Group Policy template for this log's size.
Microsoft-Windows-NTLM/Operational Log No Group Policy template for this log's size.
Microsoft-Windows-Security-Mitigations/KernelMode Log No Group Policy template for this log's size.
Microsoft-Windows-Security-Mitigations/UserMode Log No Group Policy template for this log's size.
Microsoft-Windows-PrintService/Admin Log No Group Policy template for this log's size.
Microsoft-Windows-PrintService/Operational Log No Group Policy template for this log's size or enablement.
Microsoft-Windows-SmbClient/Security Log No Group Policy template for this log's size.
Microsoft-Windows-AppLocker/EXE and DLL Log No Group Policy template for this log's size.
Microsoft-Windows-AppLocker/MSI and Script Log No Group Policy template for this log's size.
Microsoft-Windows-AppLocker/Packaged app-Deployment Log No Group Policy template for this log's size.
Microsoft-Windows-AppLocker/Packaged app-Execution Log No Group Policy template for this log's size.
Microsoft-Windows-CodeIntegrity/Operational Log No Group Policy template for this log's size.
Microsoft-Windows-Diagnosis-Scripted/Operational Log No Group Policy template for this log's size.
Microsoft-Windows-DriverFrameworks-UserMode/Operational Log No Group Policy template for this log's size or enablement.
Microsoft-Windows-WMI-Activity/Operational Log No Group Policy template for this log's size.
Microsoft-Windows-TerminalServices-LocalSessionManager/Operational Log No Group Policy template for this log's size.
Microsoft-Windows-TerminalServices-RemoteConnectionManager/Operational Log No Group Policy template for this log's size or enablement.
Microsoft-Windows-RemoteDesktopServices-RdpCoreTS/Operational Log No Group Policy template for this log's size or enablement.
Microsoft-Windows-TaskScheduler/Operational Log No Group Policy template for this log's size or enablement.
Microsoft-Windows-SMBServer/Audit Log No Group Policy template for this log's size.
Microsoft-Windows-SmbClient/Audit Log No Group Policy template for this log's size.
Microsoft-Windows-SMBServer/Security Log No Group Policy template for this log's size or enablement.
Microsoft-Windows-SMBServer/Operational Log No Group Policy template for this log's size or enablement.
Microsoft-Windows-Crypto-DPAPI/Debug Log No Group Policy template for this log's size or enablement.
AdcsAuditFilter Registry No Group Policy template, and it needs a CertSvc restart: set it on the CA in a change window (Enable-LoggingBaseline.ps1 there).