We recently did this ourselves. LEM won't monitor an OU, only a security group. We created a security group in AD called "service accounts". Placed all our service accounts in there. When we created the rule for interactive logins, we just located the new security group via "directory services" in LEM. works like a charm.
↧