Unfortunately I have not had any luck.
Here is the Windows Event XML that I would want excepted from the stock rule because of the active user is "adsync":- <Event xmlns="
http://schemas.microsoft.com/win/2004/08/events/event">
- <System>
<Provider Name="Microsoft-Windows-Security-Auditing" Guid="{54849625-5478-4994-a5ba-3e3b0328c30d}" />
<EventID>4662</EventID>
<Version>0</Version>
<Level>0</Level>
<Task>14080</Task>
<Opcode>0</Opcode>
<Keywords>0x8020000000000000</Keywords>
<TimeCreated SystemTime="2024-05-24T18:52:47.8899705Z" />
<EventRecordID>31908609</EventRecordID>
<Correlation />
<Execution ProcessID="776" ThreadID="888" />
<Channel>Security</Channel>
<Computer>ad.foo.bar</Computer>
<Security />
</System>
- <EventData>
<Data Name="SubjectUserSid">S-1-5-21-3553857315-2347844133-1096870106-4216</Data>
<Data Name="SubjectUserName">adsync</Data>
<Data Name="SubjectDomainName">foo.bar</Data>
<Data Name="SubjectLogonId">0x154e5a09</Data>
<Data Name="ObjectServer">DS</Data>
<Data Name="ObjectType">%{19195a5b-6da0-11d0-afd3-00c04fd930c9}</Data>
<Data Name="ObjectName">%{1b20f7f1-991f-4938-ae59-6c09f393eccf}</Data>
<Data Name="OperationType">Object Access</Data>
<Data Name="HandleId">0x0</Data>
<Data Name="AccessList">%%7688</Data>
<Data Name="AccessMask">0x100</Data>
<Data Name="Properties">%%7688 {1131f6ad-9c07-11d1-f79f-00c04fc2dcd2} {19195a5b-6da0-11d0-afd3-00c04fd930c9}</Data>
<Data Name="AdditionalInfo">-</Data>
<Data Name="AdditionalInfo2" />
</EventData>
</Event>