2003 DC auditing issue

From: SG (SG_at_discussions.microsoft.com)
Date: 12/09/04


Date: Thu, 9 Dec 2004 04:19:08 -0800

I have Windows 2003 test machine , and I test auditing policies .

Configuration
========
2003 Domain Controller , with default installation settings .

Symptoms
======
If I configure all audit policies in “Default Domain Controllers Policy” to
“Not configured” ( not “No Auditing” ) – as expected - nothing is audited.

If I then, configure a single ( no matter which one ) Audit Policy ( say
Audit Account Management ) to Audit Success and Audit Failure , as expected
- Account Management events are being log , HOWEVER , Event IDs which belong
to other Security Categories are ALSO being log in Security Event Viewer.
That is – I receive logs for Logon/Logoff , Account logon, Privilege Use and
so on.

Why is this behavior ? I expected to receive only logs sourced by Account
Management policy as it was the only set on.

I used GPMC Results to make sure no other scoped GPOs have auditing enabled.



Relevant Pages

  • Re: ADAM object auditing
    ... Enabling the audit will not help for ADAM, ... type of output I get from enabling Account Management in AD (all creates, ... check the SACL box, click OK. ...
    (microsoft.public.windows.server.active_directory)
  • Re: ADAM object auditing
    ... Enabling the audit will not help for ADAM, ... type of output I get from enabling Account Management in AD (all creates, ... check the SACL box, click OK. ...
    (microsoft.public.windows.server.active_directory)
  • Re: Auditing Account management events
    ... Simply enable auditing of "account management" in the ... security policy of the computer where you want to track these events. ... are tracking events for domain users, enable auditing of account management ... in Domain Controller Security Policy and view the security logs of the ...
    (microsoft.public.win2000.group_policy)
  • Re: user accounts are reappearing
    ... is a policy setting called "audit account management" that you can enable. ...
    (microsoft.public.win2000.active_directory)
  • Re: Event 861 fills event log on newly built Domain Controller
    ... seems to be set to audit failures. ... promoted it to a domain controller, ... Process identifier: 772 ... User account: NETWORK SERVICE ...
    (microsoft.public.windows.server.active_directory)