Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
kiikoo15
Explorer

Event 4719 Triggered After Installing Check Point EDR on Domain Controllers

Hello everyone,

I’m experiencing an issue with Check Point’s Endpoint Detection and Response (EDR) solution after deploying it on our Domain Controllers. Since installation, the servers consistently generate Event ID 4719, which logs a change to the audit policy. This event is recurring and happens multiple times a day.

I understand that Event 4719 indicates a modification in the security audit policy, but I’m unsure why the EDR is causing this on domain controllers specifically. Is this behavior expected when installing the Check Point EDR on DCs, or is there a configuration issue at play?

Additionally, I would like to know if there’s a way to fine-tune the EDR settings to prevent this from happening. I’ve reviewed the EDR’s configuration but haven’t pinpointed a way to stop these events from occurring.

Has anyone else encountered this issue? If so, how did you address it? Any guidance on configuring the EDR or audit policy to mitigate these events would be greatly appreciated.

Thanks in advance!

0 Kudos
3 Replies
PhoneBoy
Admin
Admin

What version of client?
Have you looked into the Event logs to see exactly WHAT has changed?

0 Kudos
Chris_Atkinson
Employee Employee
Employee

Which endpoint client version is installed, what blades are deployed and is the server optimisations config used as below?

https://sc1.checkpoint.com/documents/Infinity_Portal/WebAdminGuides/EN/Harmony-Endpoint-Admin-Guide/...

CCSM R77/R80/ELITE
0 Kudos
kiikoo15
Explorer

My verison is  88.41.1002

The blades deployed are:

  • Files Protection
  • Anti ransomware 
  • Anti-exploit (Detect)
  • Analysis and remediation
  • And i have a rule with server optimisation (Domain Controller)
0 Kudos

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    CheckMates Events