Skip to content
arrow_back
search
ISM-1830 policy ASD Information Security Manual (ISM)

Central Logging for Microsoft AD Server Activities

Log important actions on Microsoft AD servers in a central location for better monitoring.

record_voice_over

Plain language

This control means that actions taken on Microsoft Active Directory servers should be recorded in a central spot. This is important because if something goes wrong, like a security breach, you want to quickly find out what happened and who did what, so you can fix it and prevent it from happening again.

Framework

ASD Information Security Manual (ISM)

Control effect

Detective

Classifications

NC, OS, P, S, TS

ISM last updated

Aug 2024

Control Stack last updated

19 Mar 2026

E8 maturity levels

N/A

Official control statement

Security-relevant events for Microsoft AD DS domain controllers, Microsoft AD CS CA servers, Microsoft AD FS servers and Microsoft Entra Connect servers are centrally logged.
policy ASD Information Security Manual (ISM) ISM-1830
priority_high

Why it matters

Without central logging, AD DS/CS/FS and Entra Connect security events may be missed, delaying detection, response and recovery.

settings

Operational notes

Configure domain controllers, AD CS/FS and Entra Connect to forward security-relevant events to a central log store; review alerts regularly.

Mapping detail

Mapping

Direction

Controls