Re: What should be audited on a DC

From: Samantha (anonymous_at_discussions.microsoft.com)
Date: 05/13/04

  • Next message: Tim: "Re: How to link a login to a database user"
    Date: Wed, 12 May 2004 20:26:05 -0700
    
    

    Thank you Steven
         
         ----- Steven L Umbach wrote: -----
         
         That depends on what you want to monitor and how much time you have to do
         such. Generally for domain controllers you want to audit at least account
         logon events for sucess and failure and probably system events, policy
         change, and account management. If you audit everything then your logs fill
         up very quickly with events that make it hard to see what you really need to
         see and can impair performance on your computers. There may be other
         categories you may want to audit on certain occassions [such as object
         access/folder auditing] or for situations that require higher level of
         security. Be sure to increase the size of your security logs quite a bit
         from default and learn how to use the filter view and free tools like Event
         Comb. The links below may be helpful. --- Steve
         
         http://www.microsoft.com/technet/security/guidance/secmod144.mspx
         http://www.microsoft.com/technet/Security/topics/hardsys/tcg/tcgch03.mspx
         http://www.microsoft.com/technet/Security/prodtech/win2000/win2khg/05sconfg.mspx
         
         "Samantha" <anonymous@discussions.microsoft.com> wrote in message
         news:7DD9660A-92E6-4202-A994-83CCCC030F0D@microsoft.com...
    > Hi All,
    >> What audit policies should I configured to be view in event viewer on a
         Domain Controller?
    >> Many thanks
         
         
         


  • Next message: Tim: "Re: How to link a login to a database user"

    Relevant Pages

    • Re: Auditing access to files and folders
      ... Audit policy on the DCs (default domain controllers policy) includes ... Maybe you're checking the wrong log viewer. ...
      (microsoft.public.win2000.security)
    • Re: I need a Step-by-Step to set up file deletion Auditing on SBS...
      ... Default Domain Controllers Policy. ... Right-click Domain Controllers, click Properties. ... Click Computer Configuration, double-click Windows Settings, double-click ... Audit Policy. ...
      (microsoft.public.windows.server.sbs)
    • Re: Windows 2000 Auditing Object Access
      ... One of the domain controllers is our File and Print server. ... server that I would like to audit files. ... In addition to that, several sub-categories under Security ... > you do it on an OU which contain your servers. ...
      (microsoft.public.windows.server.general)
    • Re: What should be audited on a DC
      ... Generally for domain controllers you want to audit at least account ... change, and account management. ... Be sure to increase the size of your security logs quite a bit ...
      (microsoft.public.win2000.security)
    • Re: W2K3 R2 is not logging/auditing failure events
      ... Audit Account Logon Events, and selected audit success and failure. ... Try to configure the domain account audit settings at the Default Domain Controllers OU as the domain controllers are the ones that will have to audit those. ...
      (microsoft.public.windows.group_policy)