Defender for identity configure windows collection

Elie Attieh 41 Reputation points
2023-08-31T09:57:37.81+00:00

Hello,

Kindly i need to know if is it risky to enable audit permissions for everyone when configuring object auditing? im working on defender for identity global health issues from this article https://video2.skills-academy.com/en-us/defender-for-identity/configure-windows-event-collection#configure-audit-policies

Regards,

Microsoft Defender for Identity
Microsoft Defender for Identity
A Microsoft service that helps protect enterprise hybrid environments from multiple types of advanced, targeted cyberattacks and insider threats.
175 questions
0 comments No comments
{count} votes

1 answer

Sort by: Most helpful
  1. Fiona Matu 86 Reputation points Microsoft Employee
    2024-01-30T14:13:39.42+00:00

    Hi @Elie Attieh

    From the link you shared, I deduce that audit permissions were granted to the specified Principal member within the set of "Everyone" and the object was "Everyone" for which all its members could be audited by the principal. I therefore do not think the specified approach is risky.

    0 comments No comments