Audit AD GPO changes

Assuming you've already got AD object auditing turned on, the following XML XPath filter can filter the Security log of a DC to only return the events related to AD GPO changes <QueryList> <Query Id="0" Path="Security"> <Select Path="…