Skip to main content
Microsoft has a document that shows exempting certain Active Directory files from scanning, in this document found here: https://support.microsoft.com/en-us/kb/822158

 

For Domain Controllers is it necessary or recommended to exclude any of these items?
It shouldn't be - as long as you use the Recommended Server Defaults policy then you should be good to go. If you do run into any issues just let us know and we can get it sorted out.

Reply