Security Monitoring: Member Server Special Group Logon

Security.Monitoring.SpecialGroupLogonEnabledOnMemberServers (UnitMonitor)

This monitor watches the audit policy settings for Special Group Logon. See https://blogs.technet.microsoft.com/jepayne/2015/11/26/tracking-lateral-movement-part-one-special-groups-and-specific-service-accounts/ for details.

Element properties:

TargetMicrosoft.Windows.Computer
Parent MonitorSystem.Health.ConfigurationState
CategoryAvailabilityHealth
EnabledFalse
Alert GenerateFalse
Alert Auto ResolveTrue
Monitor TypeSecurity.Monitoring.AuditPolMonitorType
RemotableTrue
AccessibilityInternal
RunAsDefault

Source Code:

<UnitMonitor ID="Security.Monitoring.SpecialGroupLogonEnabledOnMemberServers" Accessibility="Internal" Enabled="false" Target="Windows!Microsoft.Windows.Computer" ParentMonitorID="Health!System.Health.ConfigurationState" Remotable="true" Priority="Normal" TypeID="Security.Monitoring.AuditPolMonitorType" ConfirmDelivery="false">
<Category>AvailabilityHealth</Category>
<OperationalStates>
<OperationalState ID="ResultBad" MonitorTypeStateID="ResultBad" HealthState="Warning"/>
<OperationalState ID="ResultGood" MonitorTypeStateID="ResultGood" HealthState="Success"/>
</OperationalStates>
<Configuration>
<IntervalSeconds>86400</IntervalSeconds>
<SyncTime/>
<SubCommandAuditSetting>Special Logon</SubCommandAuditSetting>
<Result>Success and Failure</Result>
</Configuration>
</UnitMonitor>