DirectAccess Tracing/Tracking Endpoints
hi
we have couple of different devices such fireeye, arcsite, epo track threats on our infrastructure. we've noticed when threat detected on directaccess given directaccess server endpoint rather client connecting in through this. there way trace connections , record log values of people connect? noticed internal report gives results if run report or run powershell command export information csv.
not sure if makes difference of our connections utilize teredo , not have reverse ipv6 lookup zones.
hi,
>>is there way trace connections , record log values of people connect?
as far know, internal report build-in function trace da session.
as workaround, can configure audit on internal resource servers, when directaccess users access internal resource, it audited.
best regards.
steven lee please remember mark replies answers if , unmark them if provide no help. if have feedback technet support, contact tnmff@microsoft.com.
Windows Server > Security
Comments
Post a Comment