STIGQter STIGQter: STIG Summary: Active Directory Domain Security Technical Implementation Guide Version: 3 Release: 7 Benchmark Date: 01 Apr 2026:

Windows Server domain controllers must have Kerberos logging enabled with servers hosting Active Directory Certificate Services (AD CS).

DISA Rule

SV-269097r1026170_rule

Vulnerability Number

V-269097

Group Title

SRG-OS-000480

Rule Version

AD.0205

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

Navigate to Local Computer Policy >> Computer Configuration >> Windows Settings >> Security Settings >> Local Policies >> Advanced Audit Policy Configuration >> System Audit Policies >> Account Logon.

Configure "Audit Kerberos Authentication Service" and the "Audit Kerberos Service Ticket Operations" to be set to "Success and Failure".

Check Contents

This applies to domain controllers only. It is not applicable for other systems. Verify the following is configured on the domain controller.

Navigate to Local Computer Policy >> Computer Configuration >> Windows Settings >> Security Settings >> Advanced Audit Policy Configuration >> System Audit Policies >> Account Logon.

If "Audit Kerberos Authentication Service" and "Audit Kerberos Ticket Operations" are not set to "Success and Failure", this is a finding.

Vulnerability Number

V-269097

Documentable

False

Rule Version

AD.0205

Severity Override Guidance

This applies to domain controllers only. It is not applicable for other systems. Verify the following is configured on the domain controller.

Navigate to Local Computer Policy >> Computer Configuration >> Windows Settings >> Security Settings >> Advanced Audit Policy Configuration >> System Audit Policies >> Account Logon.

If "Audit Kerberos Authentication Service" and "Audit Kerberos Ticket Operations" are not set to "Success and Failure", this is a finding.

Check Content Reference

M

Target Key

5406