Join us at Gartner SEC London and discover how LevelBlue can help you secure what’s next. Learn More
Access immediate incident response support, available 24/7
When The AD Agent scans through the AD security logs, it will look for logon and logoff events generated by users, and have the R3000 set/remove profiles based on this. Specifically, the Agent will respond to events with event ID 672 and 673. If the AD security logs do not contain any events of this ID, then the Agent will not perform any authentication actions.
To contact LevelBlue about this article or to request support: