Hello everyone,
I’m experiencing an issue with Check Point’s Endpoint Detection and Response (EDR) solution after deploying it on our Domain Controllers. Since installation, the servers consistently generate Event ID 4719, which logs a change to the audit policy. This event is recurring and happens multiple times a day.
I understand that Event 4719 indicates a modification in the security audit policy, but I’m unsure why the EDR is causing this on domain controllers specifically. Is this behavior expected when installing the Check Point EDR on DCs, or is there a configuration issue at play?
Additionally, I would like to know if there’s a way to fine-tune the EDR settings to prevent this from happening. I’ve reviewed the EDR’s configuration but haven’t pinpointed a way to stop these events from occurring.
Has anyone else encountered this issue? If so, how did you address it? Any guidance on configuring the EDR or audit policy to mitigate these events would be greatly appreciated.
Thanks in advance!