Domain Controller Policy
If your domain controllers need to replicate across sites you should implement secure connections between the sites.
Domain controller policy. Default domain controllers policy one well known application that directly modifies the default domain controllers policy is microsoft exchange. The installer adds the exchange servers group to the manage auditing and security log user right also referred to as sacl right. The domain controller gathers the list of group policy objects by searching the parent containers of the domain controller s computer object.
This means you only need to implement the policy once rather than having to repeat it for every dc. Every dc has by default the default domain controllers policy in place but this gpo creates different escalation paths to domain admin if you have any members in backup operators or server operators for example. Please note that the activation of audit policy may be delayed on the domain controllers dcs depending on your replication interval.
The domain controller applies the settings listed earlier only if the group policy object is linked to the domain container. Basically default settings of domain controllers are not hardened.