DirectAccess Tracing/Tracking Endpoints


hi

we have couple of different devices such fireeye, arcsite, epo track threats on our infrastructure.  we've noticed when threat detected on directaccess given directaccess server endpoint rather client connecting in through this.  there way trace connections , record log values of people connect? noticed internal report gives results if run report or run powershell command export information csv.

not sure if makes difference of our connections utilize teredo , not have reverse ipv6 lookup zones. 

hi,

>>is there way trace connections , record log values of people connect?

as far know, internal report build-in function trace da session.

as workaround, can configure audit on internal resource servers, when directaccess users access internal resource, it audited.

best regards.


steven lee please remember mark replies answers if , unmark them if provide no help. if have feedback technet support, contact tnmff@microsoft.com.



Windows Server  >  Security



Comments

Popular posts from this blog

2008 Windows Deployment Server Properties Error

Domain migration ERR3:7075 Failed to change domain affiliation, hr=8007054a This operation is only allowed for the Primary Domain Controller of the domain

How do a find data in one file, search for it in another file and if not found, write a custom message to another file