Enable LDAP server events logging using GPO

  1. On a domain controller or a system with Remote Server Administration Tools (RSAT) installed, open the Group Policy Management Console (GPMC).
  2. Create a new Group Policy Object (GPO): Right-click on the domain or organizational unit (OU) where your domain controllers reside, then select Create a GPO in this domain, and Link it here.... Give it a descriptive name, e.g. Domain Controller Registry Settings.
  3. Edit the GPO.
    1. Right-click on the newly created GPO and select Edit.

      image33.png

    2. In the Group Policy Management Editor, navigate to Computer ConfigurationPreferencesWindows SettingsRegistry.

      image18.png

    3. Add Registry Items: Right-click on Registry and select NewRegistry Item.

      image36.png

    4. Configure Registry Keys: For each of the registry keys you want to set, create a new Registry Item.

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\NTDS\Diagnostics]

Create the following Registry item:

15 Field Engineering

  • Action: Update
  • Hive: HKEY_LOCAL_MACHINE
  • Key Path: SYSTEM\CurrentControlSet\Services\NTDS\Diagnostics
  • Value name: 15 Field Engineering
  • Value type: REG_DWORD
  • Value data: 5

| |
| ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\NTDS\Parameters]

Create the following Registry items:

Expensive Search Results Threshold

  • Action: Update
  • Hive: HKEY_LOCAL_MACHINE
  • Key Path: SYSTEM\CurrentControlSet\Services\NTDS\Parameters
  • Value name: Expensive Search Results Threshold
  • Value type: REG_DWORD
  • Value data: 1

| |
| ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |

Inefficient Search Results Threshold

  • Action: Update
  • Hive: HKEY_LOCAL_MACHINE
  • Key Path: SYSTEM\CurrentControlSet\Services\NTDS\Parameters
  • Value name: Inefficient Search Results Threshold
  • Value type: REG_DWORD
  • Value data: 1

| |
| ---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |

Search Time Threshold (msecs)

  • Action: Update
  • Hive: HKEY_LOCAL_MACHINE
  • Key Path: SYSTEM\CurrentControlSet\Services\NTDS\Parameters
  • Value name: Search Time Threshold (msecs)
  • Value type: REG_DWORD
  • Value data: 1

| |
| ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |

  1. Close the Group Policy Management Editor.
  2. To link the GPO to the OU where your domain controllers reside, in Group Policy Management, right-click the OU, select Link an Existing GPO, then select the GPO you just created.\
  3. Force Group Policy Update: Force a Group Policy update using the gpupdate /force command on each domain controller or by restarting them.