System Active Directory Change Monitor
This option group section of the policy monitors specific Active Directory-based events. These events include potentially suspicious domain trust events, FSMO changes, and authentication or encryption configuration changes. These events may be indicative of malicious configuration, which may affect the Active Directory system itself, as well as downstream systems.