AD Core refers to core metrics and performance indicators for Active Directory. Active Directory (AD) is a directory service developed by Microsoft for Windows domain networks and is included in most Windows Server operating systems. It provides a variety of directory services including authentication, authorization, and accounting.
These thresholds are the Threshold Configuration settings found under the "Domain Controllers -> AD Core" section of the ENow Admin Console, which is focused on the Active Directory metrics of domain controllers.
Where these thresholds are set: the values that apply to your environment are configured in the ENow Admin Console, under Server > Tuning Policy > Agent Options. Each check is evaluated against the threshold set there, so confirm the current values in your own console rather than assuming the examples below.
AD Time:
If the domain controller's time drifts from the primary domain controller (PDC) emulator by more than the warning or critical threshold configured for this check, an alert is triggered. Time synchronization is critical in AD environments for logon, replication, and various security protocols — Kerberos rejects authentication once clock skew exceeds the domain's maximum tolerance, which is five minutes by default.
See: Configure an authoritative time - Windows Server | Microsoft Learn
AD Partition Backup:
Backing up Active Directory, and ensuring successful restores in cases of corruption, compromise or disaster is a critical part of Active Directory maintenance. This check reports how long it has been since a backup was taken, and raises a warning and then a critical alert once that age passes the thresholds configured for the check. Regular backups are important for disaster recovery.
See: Back up and restore Active Directory - Azure Backup | Microsoft Learn
AD LDAP Bind Time:
This indicator measures how long it takes for a Lightweight Directory Access Protocol (LDAP) bind (authentication request) to occur. A warning and then a critical alert are raised once the bind time passes the thresholds configured for the check. LDAP binds should be quick; longer times can indicate performance issues.
See: LDAP considerations in ADDS performance tuning | Microsoft Learn
AD LDAP Client Sessions:
A client session in the context of AD and LDAP refers to the interaction between a client (e.g., a user's computer or an application) and the directory server. We monitor the number of simultaneous LDAP client sessions on AD, raising a warning and then a critical alert once the session count passes the thresholds configured for the check. High numbers might indicate heavy usage or potential misuse.
AD LDAP Searches Per Second:
This metric shows how many LDAP searches are being performed every second. Once the search rate passes the thresholds configured for the check, a warning and then a critical alert are triggered. High search rates may impact performance.
AD LDAP Expensive Searches:
These are searches that consume significant resources. A warning and then a critical alert are triggered once the count passes the thresholds configured for the check. Monitoring these searches helps in identifying and mitigating inefficient queries.
AD LSASS Percent CPU Usage:
LSASS is the Local Security Authority Subsystem Service. A warning is issued once LSASS CPU usage passes the warning threshold configured for the check, and it becomes critical once usage passes the critical threshold. High LSASS CPU usage could indicate a security issue or misconfiguration.
Repadmin Last Error:
Repadmin is a command-line tool for diagnosing AD replication issues. This check reports how long it has been since the last replication error was recorded, and raises a warning and then a critical alert once that age passes the thresholds configured for the check. Frequent replication errors could point to network or server issues.
See: Troubleshooting AD replication - Windows Server | Microsoft Learn
Comments
0 comments
Please sign in to leave a comment.