Skip to main content

Active Directory Folder Templates

The Templates > Microsoft > Active Directory folder in the Navigation pane contains the following templates:

Authentication Folder

SubfolderTemplateDescriptionTAGS
AD: Failed Account AuthenticationsGathers Failed AD Authentications.
Uses built-In “Failed Authentications” – Include Perpetrators Collection to define which accounts will be monitored for failed authentications. Add accounts to be monitored to this collection.
None
AD: Successful Account AuthenticationsGathers Successful AD Authentications.
Uses built-In “Successful Authentications” – Include Perpetrators Collection to define which accounts will be monitored for successful authentications. Add accounts to be monitored to this collection.
None
AD: Successful Account LogonsNo customizations required. Most common modification: specify a list of users (AD Objects) to be included or excluded.
Ensure the Exclude 'Noise' Events option on the Event Filtering Configuration Window is Off for this policy.
None
Administrative AccountsAD: Domain Administrators Logons to Non Domain ControllersGathers logon events of Domain Administrator accounts to non-domain controller computes.
Uses built-In “Domain Administrators” – Include Perpetrators Collection to define which accounts will be monitored for logons. Add accounts which have domain administrator rights to be monitored to this collection.
Also uses built-In “Domain Controllers” – Hosts Collection to define which hosts will NOT be monitored for logons. Add domain controllers to be ignored to this collection.
None
Administrative AccountsAD: Failed Administrator Account AuthenticationsGathers AD: Failed Administrator Account Authentications.
Uses built-In “Administrative Accounts” – Include Perpetrators Collection to define which administrative accounts will be monitored for failed authentications.
None
Administrative AccountsAD: Successful Administrator Account AuthenticationsGathers Successful AD Authentications for Administrators.
Uses built-In “Administrative Accounts” – Include Perpetrators Collection to define which administrative accounts will be monitored for successful authentications. Add accounts with administrative rights to be monitored to this collection.
None
Administrative AccountsAD: Successful Administrator Account LogonsUses built-in “Administrator Accounts” – Objects Collection. Add accounts with administrator rights to be monitored to this collection
Ensure the Exclude 'Noise' Events option on the Event Filtering Configuration Window is Off for this policy
None
Service AccountsAD: Failed Service Account AuthenticationsGathers Failed AD Authentications for service accounts.
Uses built-In “Service Accounts” – Include Perpetrators Collection to define which service accounts will be monitored for failed authentications. Add service accounts to be monitored to this collection
None
Service AccountsAD: Successful Service Account AuthenticationsGathers Successful AD Authentications for service accounts.
Uses built-In “Service Accounts” – Include Perpetrators Collection to define which service accounts will be monitored for successful authentications. Add service accounts to be monitored to this collection
None
Service AccountsAD: Successful Service Account LogonsUses built-in "Service Accounts" – Objects Collection. Add service accounts to be monitored to this collection
Ensure the Exclude 'Noise' Events option on the Event Filtering Configuration Window is Off for this policy.
None

Groups Folder

SubfolderTemplateDescriptionTAGS
AD Group CreationsNo customizations required. Most common modifications: specify AD Perpetrator to be included or excludedNone
AD Group DeletionsNo customizations required. Most common modifications: specify AD Perpetrator to be included or excludedNone
AD: Group Membership ChangesNo customizations required. Most common modifications: specify AD Objects and/or AD Perpetrator to be included or excludedNone
AD: Group Moves or RenamesNo customizations required. Most common modifications: specify AD Perpetrator to be included or excludedNone
AD Group Type ModificationsNo customizations required. Most common modifications: specify AD Objects and/or AD Perpetrator to be included or excluded
Administrative AccountsAD: Group Deletions by AdministratorsUses built-in "Administrative Accounts" – Perpetrator Collection. Add accounts with administrative rights to be monitored to this collectionNone
Administrative AccountsAD: Group Deletions by Non-AdministratorsUses built-in “Administrative Accounts” – Perpetrator Collection. Add accounts with administrative account to NOT be monitored to this collectionNone
Administrative AccountsAD: Group Membership Changes by AdministratorsUses built-in "Administrative Accounts" – Perpetrator Collection. Add accounts with administrative rights to be monitored to this collectionNone
Administrative AccountsAD Group Membership Changes by Non-AdministratorsUses built-in “Administrative Accounts” – Perpetrator Collection. Add accounts with administrative account to NOT be monitored to this collectionNone
Administrative AccountsAD: Group Moves or Renames by AdministratorsUses built-in "Administrative Accounts" – Perpetrator Collection. Add accounts with administrative rights to be monitored to this collectionNone
Administrative AccountsAD: Group Moves or Renames by Non-AdministratorsUses built-in “Administrative Accounts” – Perpetrator Collection. Add accounts with administrative account to NOT be monitored to this collection.None
Administrative GroupsAD: Deletions of Administrator GroupsUses the built-in “Administrator Groups” – Objects Collection. Add administrator groups to be monitored to this collectionNone
Administrative GroupsAD: Group Membership Changes to Administrator GroupsUses the built-in “Administrator Groups” – Objects Collection. Add administrator groups to be monitored to this collectionNone
Administrative GroupsAD: Moves or Renames of Administrator GroupsUses the built-in “Administrator Groups” – Objects Collection. Add administrator groups to be monitored to this collectionNone

Lockdown Folder

warning

Use caution with all Lockdown/Blocking Templates. Blank filters result in everything being locked down or blocked.

TemplateDescriptionTAGS
AD Generic LockdownSet the appropriate AD event types to be blocked. Then select the AD Objects, Containers, Classes, and Attributes and Perpetrators you want to allow or denyNone
Auth Generic LockdownSet the appropriate AD Perpetrators and/or Hosts to be blockedNone

Organizational Unit Folder

TemplateDescriptionTAGS
AD OU CreationsNo customizations required. Most common modifications: specify AD Perpetrator to be included or excludedNone
AD OU DeletionsNo customizations required. Most common modifications: specify AD Perpetrator to be included or excludedNone
AD OU ModificationsNo customizations required. Most common modifications: specify AD Perpetrator to be included or excludedNone
AD OU Moves or RenamesNo customizations required. Most common modifications: specify AD Perpetrator to be included or excludedNone
AD OU Security ModificationsNo customizations required. Most common modifications: specify AD Perpetrator to be included or excludedNone

Password Enforcement Folder

TemplateDescriptionTAGS
Password Enforcement MonitoringNo customizations required. Prevents users from changing a password to any value in the Threat Prevention dictionary of known compromised passwordsNone

Replication Folder

TemplateDescriptionTAGS
AD Replication LockdownUSE CAUTION WITH ALL LOCKDOWN TEMPLATES
Prevents Active Directory data synchronization requests from non-domain controllers using RPC call IDL_DRSGetNCChanges. Add legitimate domain controllers to be inored in one of the following ways to prevent them from being blocked:
  • Allow Perpetrators List – Add the Users OU > Domain Controllers group and any other groups with domain controllers for a dynamic list of domain controllers
  • Exclude Domains/Servers – Add specific domain controllers for a static list of domain controllers
See the AD Replication Lockdown Event Type topic for additional information.
None
AD Replication MonitoringUses the built-in “Domain Controllers” – Hosts Collection. Add domain controllers to not be monitored.
Alternatively, add legitimate domain controllers to be ignored in one of the following ways:
  • Exclude Perpetrators List – Add the Users OU > Domain Controllers group and any other groups with domain controllers for a dynamic list of domain controllers
  • Exclude Domains/Servers – Add specific domain controllers for a static list of domain controllers
See the AD Replication Monitoring Event Type topic for additional information.
None

Server-Workstation Folder

TemplateDescriptionTAGS
AD: Computer Account CreationsNo customizations required. Most common modifications: specify AD Perpetrator to be included or excludedNone
AD: Computer Account DeletionsNo customizations required. Most common modifications: specify AD Perpetrator to be included or excludedNone
AD: Computer Account ModificationsNo customizations required. Most common modifications: specify AD Perpetrator to be included or excludedNone

Users Folder

SubfolderTemplateDescriptionTAGS
AD: User Account CreationsNo customizations required. Most common modifications: specify AD Perpetrator to be included or excludedNone
AD: User Account DeletionsNo customizations required. Most common modifications: specify AD Objects and/or AD Perpetrator to be included or excludedNone
AD: User Account LockoutsNo customizations required. Most common modifications: specify AD Objects to be included or excludedNone
AD: User Account ModificationsNo customizations required. Most common modifications: specify AD Objects and/or AD Perpetrator to be included or excludedNone
AD: User Account Moves and RenamesNo customizations required. Most common modifications: specify AD Objects and/or AD Perpetrator to be included or excludedNone
AD: User Account Password SetNo customizations required. Most common modifications: specify AD Objects and/or AD Perpetrator to be included or excludedNone
Administrative AccountsAD: Deletions of Administrator AccountsUses built-in “Administrator Accounts” – Objects Collection. Add accounts with administrator rights to be monitored to this collectionNone
Administrative AccountsAD: Modifications of Administrator AccountsUses built-in “Administrator Accounts” – Objects Collection. Add accounts with administrator rights to be monitored to this collectionNone
Administrative AccountsAD: Moves and Renames of Administrator AccountsUses built-in “Administrator Accounts” – Objects Collection. Add accounts with administrator rights to be monitored to this collectionNone
Administrative AccountsAD: Password Set on Administrator AccountsUses built-in “Administrator Accounts” – Objects Collection. Add accounts with administrator rights to be monitored to this collectionNone
Administrative AccountsAD: User Creations by AdministratorsUses built-in "Administrative Accounts" – Perpetrator Collection. Add accounts with administrative rights to be monitored to this collectionNone
Administrative AccountsAD: User Creations NOT by AdministratorsUses the built-in “Administrative Accounts” – Perpetrator Collection. Add accounts with administrative rights to NOT be monitored to this collectionNone
Administrative AccountsAD: User Deletions by AdministratorsUses built-in "Administrative Accounts" – Perpetrator Collection. Add accounts with administrative rights to be monitored to this collectionNone
Administrative AccountsAD: User Deletions NOT by AdministratorsUses the built-in “Administrative Accounts” – Perpetrator Collection. Add accounts with administrative rights to NOT be monitored to this collectionNone
Administrative AccountsAD: User Modifications by AdministratorsUses built-in "Administrative Accounts" – Perpetrator Collection. Add accounts with administrative rights to be monitored to this collectionNone
Administrative AccountsAD: User Modifications NOT by AdministratorsUses the built-in “Administrative Accounts” – Perpetrator Collection. Add accounts with administrative rights to NOT be monitored to this collectionNone
Administrative AccountsAD: User Moves and Renames by AdministratorsUses built-in "Administrative Accounts" – Perpetrator Collection. Add accounts with administrative rights to be monitored to this collectionNone
Administrative AccountsAD: User Moves and Renames NOT by AdministratorsUses the built-in “Administrative Accounts” – Perpetrator Collection. Add accounts with administrative rights to NOT be monitored to this collectionNone
Service AccountsAD: Deletions of Service AccountsUses built-in "Service Accounts" – Objects Collection. Add service accounts to be monitored to this collectionNone
Service AccountsAD: Modifications of Service AccountsUses built-in "Service Accounts" – Objects Collection. Add service accounts to be monitored to this collectionNone
Service AccountsAD: Moves and Renames of Service AccountsUses built-in "Service Accounts" – Objects Collection. Add service accounts to be monitored to this collectionNone
Service AccountsAD: Password Set on Service AccountsUses built-in "Service Accounts" – Objects Collection. Add service accounts to be monitored to this collectionNone