From 6af407e2ff0707c18c3beaf8ddf0b9cb80340374 Mon Sep 17 00:00:00 2001 From: vultureman Date: Thu, 20 Nov 2025 16:02:33 -0500 Subject: [PATCH] Fix audit policy recommendation for computer accounts Per https://learn.microsoft.com/en-us/previous-versions/windows/it-pro/windows-10/security/threat-protection/auditing/audit-computer-account-management this audit type does not have failure events, so "Stronger Recommendation" should not be Yes | Yes, but Yes | No --- .../security-best-practices/Audit-Policy-Recommendations.md | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/WindowsServerDocs/identity/ad-ds/plan/security-best-practices/Audit-Policy-Recommendations.md b/WindowsServerDocs/identity/ad-ds/plan/security-best-practices/Audit-Policy-Recommendations.md index b6b20da14b..de657c9a52 100644 --- a/WindowsServerDocs/identity/ad-ds/plan/security-best-practices/Audit-Policy-Recommendations.md +++ b/WindowsServerDocs/identity/ad-ds/plan/security-best-practices/Audit-Policy-Recommendations.md @@ -47,7 +47,7 @@ These tables contain the Windows default setting, the baseline recommendations, | --- | :---: | :---: | :---: | | **Account Management** | | | | | Audit Application Group Management | | | | -| Audit Computer Account Management | | `Yes | No` | `Yes | Yes` | +| Audit Computer Account Management | | `Yes | No` | `Yes | No` | | Audit Distribution Group Management | | | | | Audit Other Account Management Events | | `Yes | No` | `Yes | Yes` | | Audit Security Group Management | | `Yes | No` | `Yes | Yes` |