Deploying MDI
Now we’ve recapped the significance of MDI for AD defense in depth, let’s discuss how it can be configured on-premises in the following section.
Getting on-premises AD ready for MDI
MDI relies on specific audit event log entries to provide detections and add additional information on who or what performed those actions on your AD Domain Services (ADDS) or AD Federation Services (ADFS) infrastructure.
The following Windows events need to be configured in the Advanced Audit Policy on each domain controller:
- 4662 – An Operation was Performed on an Object
- 4726 – User Account Deleted
- 4728 – Member Added to Global Security Group
- 4729 – Member Removed from Global Security Group
- 4730 – Global Security Group Deleted
- 4732 – Member Added to Local Security Group
- 4733 – Member Removed from Local Security Group
- 4741 – Computer Account Added
- 4743 – Computer Account...