Fix audit policy recommendation for computer accounts#8099
Fix audit policy recommendation for computer accounts#8099vultureman wants to merge 1 commit intoMicrosoftDocs:mainfrom
Conversation
Per https://learn.microsoft.com/en-us/previous-versions/windows/it-pro/windows-10/security/threat-protection/auditing/audit-computer-account-management this audit type does not have failure events, so "Stronger Recommendation" should not be Yes | Yes, but Yes | No
|
@vultureman : Thanks for your contribution! The author(s) and reviewer(s) have been notified to review your proposed change. |
|
Learn Build status updates of commit 6af407e: ✅ Validation status: passed
For more details, please refer to the build report. |
|
This also appears to be the same case for: Audit Other Account Management Events Per the link mentioned above, none of those 6 groups (5 above plus the original proposed change) have a failure type for that category, so they should be Yes | No Similarly, "Audit Account Lockout" is set to Yes | No, but per that article, the audit category only generates Failure events. So both options on "Audit Account Lockout" should be No | Yes Basically, the whole sheet should be vetted to verify if any "Stronger Recommendations" actually generate those events. |
|
@robinharwood, @Xelu86 #label:"aq-pr-triaged" |
|
Users robinharwood are already assigned. |
Per
https://learn.microsoft.com/en-us/previous-versions/windows/it-pro/windows-10/security/threat-protection/auditing/audit-computer-account-management
this audit type does not have failure events, so "Stronger Recommendation" should not be Yes | Yes, but Yes | No