Audit Detailed Directory Service Replication

This security policy setting can be used to generate security audit events with detailed tracking information about the data that is replicated between domain controllers. This audit subcategory can be useful to diagnose replication issues.

Event volume: These events can create a very high volume of event data.

If this policy setting is configured, the following events are generated. The events appear on computers running Windows Server 2008 R2 or Windows Server 2008.

  • 4928: An Active Directory replica source naming context was established.
  • 4929: An Active Directory replica source naming context was removed.
  • 4930: An Active Directory replica source naming context was modified.
  • 4931: An Active Directory replica destination naming context was modified.
  • 4934: Attributes of an Active Directory object were replicated.
  • 4935: Replication failure begins.
  • 4936: Replication failure ends.
  • 4937: A lingering object was removed from a replica.

Scope: 

Computer

Default: 

Not configured

Related content