Windows Network Policy

Sections on this page

SIEM Events

Outbound TS Connect Attempt

Outbound TS connection attempt Event Source - Microsoft-Windows-TerminalServices-ClientActiveXCore - Event Log - Microsoft-Windows-TerminalServices-RDPClient/Operational

Network Share Created

Network Share Created Event Source - Microsoft-Windows-Security-Auditing - Event Log - Security

Network Share Deleted

Network Share Deleted Event Source - Microsoft-Windows-Security-Auditing - Event Log - Security

Network Share Checked

A network share object was checked to see whether the client can be granted desired access. Event Source - Microsoft-Windows-Security-Auditing - Event Log - Security

RADIUS User Assigned IP

RADIUS authentication User assigned IP address Event Source - Microsoft-Windows-MPRMSG - Event Log - RemoteAccess

RADIUS User Authenticated

RADIUS authentication User successfully authenticated Event Source - Microsoft-Windows-MPRMSG - Event Log - RemoteAccess

RADIUS User Disconnected

RADIUS authentication User Disconnected Event Source - Microsoft-Windows-MPRMSG - Event Log - RemoteAccess

AIS Managed SIEM

Last modified March 24, 2021