Hybrid Audit in Quest On Demand allows you to monitor and analyze activity across both your on-premises and cloud-based Microsoft environments from a single, unified interface. To accomplish this, Hybrid Audit agents are installed in your Active Directory domain to monitor and record activity. You can then search and view the recorded events through On Demand's Audit functionality.
Hybrid Audit requires the following components:
-
A deployed Hybrid Audit agent that has been configured as a broker that connects with your on-premises Active Directory domains. See Working with Hybrid Audit Brokers for more details.
-
Installed Hybrid Audit agent on Domain Controllers and member servers in the appropriate Active Directory domain to record events for actions performed on those computers. See Hybrid Audit Agent Deployment for details on installing an agent.
For more details on installing and using a Hybrid Audit agent with Security Guardian, see:
To set up Hybrid Audit for Active Directory in your organization, follow these steps:
|
|
NOTE: Logon Activity Authentication Activity events require native Windows "Audit Logon events" audit policy enabled on servers. See following guide for details: Change Auditor for Logon Activity Events. |
The Agent Deployment page displays all servers in the Active Directory forest that the Hybrid Audit agent is installed in and allows you to manage agent installations across your on-premises environment. From here, you can:
-
View Hybrid Audit agent details.
-
Filter the computer list to find specific entries.
-
Install, upgrade, or uninstall agents on selected computers.
-
Track installation progress.
-
Monitor agent connection status to the Hybrid Audit Broker.
-
Run a topology scan to update your environment data.
-
Export the table view to a CSV file.
To open the Agent Deployment page:
Table 1: Available Computer Details
| Column |
Details |
| Computer Name |
The computer display name. |
| Domain |
The domain the computer belongs to. |
| Computer Type |
The computer role, such as Global Catalog, Domain Controller, Read-only Domain Controller, or Member. |
| Agent Status |
-
Not Installed – Agent has never been installed.
-
Deploying – Agent is currently being deployed.
-
Installed – Agent was installed but has never connected.
-
Connected – Agent is currently connected.
-
Disconnected – Agent was connected but is now offline.
-
Uninstalled – Agent has been removed. |
| Agent Version |
The version number of the installed agent.
An Info tip on the column header displays the latest available agent version number. |
| Last Deployment Result |
The outcome of the most recent deployment attempt. |
| Connected To |
The broker to which the computer is connected. |
|
|
NOTE: Click Filter to apply filters by column and value or click a column header to sort or filter directly. |
To install or upgrade an agent:
|
|
NOTE: You must use an account with local administrator rights on the target computer. |
-
Select the computers you want to install or upgrade the agent on.
-
Click Install/Upgrade.
-
Choose one of the following:
Once credentials are validated, the installation or upgrade process will begin.
To uninstall an agent:
-
Select the computers you want to uninstall the agent from.
-
Click Uninstall.
-
Choose one of the following:
-
Once credentials are validated, the uninstall process will begin.
To initiate a scan of your environment to update topology data:
|
|
NOTE: Run a topology scan after adding new servers or domains to ensure the Agent Deployment page reflects the latest environment. |
-
Click Run Topolgy Collection.
-
Confirm the action to scan and update the list of available servers.
To download the current table view as a CSV file:
The following section outlines how to manage Shields Up and Tier Zero Protection in environments with both Hybrid Audit and Change Auditor deployed.