The Active Directory Database Protection wizard opens when you click Add or Edit on the Active Directory Database Protection page. Using this wizard you can define the Active Directory Database processes to protect from unauthorized modifications.
Select Active Directory Database processes to protect: On the first page of the wizard, enter a name for the template and select the Active Directory database processes that are exempt from protection. | |
(Optional) Select processes exempt from protection: Select processes to exclude from protection (for example, changes made by the processes specified on this page will be excluded from protection). | |
Select one or more processes from the process list and click Add to move these processes to the exclusion list. By default, all processes (except lsass.exe) will be audited. You can also view processes on a different server or enter a process not listed in the process list. | |
The list box across the bottom of the page displays the objects that are exempt from auditing. Click Remove to remove a process from the exemption list. |
Each entry for the objects listed in the Protection template has it's individual security settings.
1 |
On the Active Directory Protection page (or Group Policy Protection page), click the + icon next to the protection template. |
For simple Active Directory attribute changes (such as Add Attribute, Modify Attribute, Delete Attribute), the Event Details pane features an option to restore changed values. When applicable, Restore Value is displayed at the top of the Event Details pane, allowing you to restore a changed value without needing to leave the client or use additional tools.
2 |
At the top of the Event Details pane, click Restore Value. |
• |
A confirmation dialog is displayed explaining that you are about to restore the value of an attribute. Click Yes to perform the restore or No to cancel the restore operation. |
• |
A confirmation dialog is displayed explaining that the restore operation is not restoring the most recent value for an attribute. Click Yes to perform the restore or No to cancel the restore operation. |
The Restore Value feature cannot be used to restore deleted objects.
© ALL RIGHTS RESERVED. Feedback Terms of Use Privacy Cookie Preference Center