Skip to content

ManageEngine ADAudit Plus

You can integrate ManageEngine ADAudit Plus with Sophos XDR so that it sends data to Sophos for analysis.

This page gives you an overview of the integration.

ManageEngine ADAudit Plus product overview

Manage Engine's ADAudit Plus is a comprehensive Active Directory (AD) audit solution that offers real-time monitoring, user and entity behavior analytics, and change auditing. It provides detailed reports on changes to AD objects, user logon activities, and Group Policy settings, ensuring compliance, security, and forensic readiness.

What we ingest

Sophos XDR collects ManageEngine ADAudit Plus events by listening for syslog that the ADAudit Plus server forwards to a Sophos XDR data collector over its SIEM integration. ADAudit Plus sends each audited report category as CEF-formatted messages that include the original AD event metadata (Windows event ID, user SID, timestamps, and report-specific context). We use the following ADAudit Plus report categories:

  • User Management reports: Active Directory user account create, modify, enable/disable, delete, lockout/unlock, and password reset activity.
  • Group Management reports: AD group creation, modification, membership changes, and deletion.
  • Computer Management reports: Computer account creation, modification, and deletion in AD.
  • GPO Management reports: Group Policy Object creation, modification, link, unlink, and deletion activity.
  • Policy Change reports: AD audit/policy and security policy change events recorded against domain controllers.
  • AD Object Auditing reports: Auditing of AD object access, permission changes, and other directory object activity (including authentication and audit-style records and health-related entries).
  • Object Creation reports: New AD object creations across the directory (including authentication- and audit-style records).
  • Azure AD Account Management reports: Account management activity for Azure AD / Microsoft Entra accounts that ADAudit Plus monitors.
  • File Audit reports: File and folder access, modification, permission change, and deletion activity from Windows file servers ADAudit Plus monitors.
  • NPS Audit reports: Network Policy Server authentication and authorization events captured by ADAudit Plus.
  • Technician Audit: Auditing of ADAudit Plus administrative/technician activity within the ADAudit Plus product itself.
  • ADAudit Plus Alerts: Alert records ADAudit Plus generates from its own alert profiles.

ManageEngine ADAudit Plus sends these messages exactly as configured in its SIEM integration. The report categories and field details that appear depend on which audit profiles, agents, and reports you have enabled and which domain controllers and file servers ADAudit Plus is monitoring.

Event and data types

We ingest the following event and data types from ManageEngine ADAudit Plus. Messages arrive as CEF over syslog from the ADAudit Plus SIEM integration and carry the original AD event metadata (Windows event ID, user SID, timestamps, and report-specific context). What you see depends on which ADAudit Plus reports, agents, and audit profiles you have enabled.

  • User account activity: User Management reports for AD user create, modify, enable/disable, delete, lockout/unlock, and password reset activity. Normalized to authentication telemetry.
  • Group and GPO management: Group Management reports (group create, modify, membership change, delete) and GPO Management reports (GPO create, modify, link, unlink, delete) from Active Directory. Normalized to authentication telemetry.
  • Computer account management: Computer Management reports for AD computer object creation, modification, and deletion. Normalized to authentication telemetry.
  • Policy changes: Policy Change reports for AD audit/policy and security policy changes recorded against domain controllers. Normalized to authentication telemetry.
  • AD object auditing: AD Object Auditing reports covering directory object access, permission changes, and related activity. Authentication-style records normalize to authentication telemetry, audit-style records normalize to cloud audit telemetry, and health-related entries normalize to generic telemetry.
  • Object creation: Object Creation reports for new AD objects across the directory. Authentication-style records normalize to authentication telemetry; audit-style records normalize to cloud audit telemetry.
  • Azure AD / Microsoft Entra account management: Azure AD Account Management reports that ADAudit Plus collects for monitored cloud accounts. Normalized to cloud audit telemetry.
  • File auditing: File Audit reports for file and folder access, modification, permission change, and deletion on Windows file servers ADAudit Plus monitors. Normalized to file modification telemetry.
  • NPS authentication: NPS Audit reports for Network Policy Server authentication and authorization events. Normalized to authentication telemetry.
  • ADAudit Plus technician activity: Technician Audit records for administrative activity inside the ADAudit Plus product. Authentication-style records normalize to authentication telemetry; audit-style records normalize to cloud audit telemetry.
  • ADAudit Plus alerts: Alert records ADAudit Plus generates from its own alert profiles. Normalized to third-party security alert telemetry.
  • Other ADAudit Plus events: ADAudit Plus messages that do not match a more specific category above. Normalized to generic telemetry.

Data provided by this integration

Data provided by ManageEngine ADAudit Plus gets normalized to the following schemas:

  • auth
  • cloudaudit
  • filemod
  • generic
  • thirdpartyalert

For more information about using schemas in Data Lake Search, see Schemas and logical types.

Vendor documentation