Re: Monitor the Adminstrator

From: Steven L Umbach (n9rou_at_n0-spam-for-me-comcast.net)
Date: 07/13/04


Date: Tue, 13 Jul 2004 16:48:13 GMT

You can't realistically restrict an administrator. You can monitor events by
auditing, though an administrator can clear the security log which in itself will
leave an event, and a malicious administrator could modify the security log. While it
is a good idea to audit, you really need to trust people that are administrators and
in W2K for AD, delegation can be used to do most things without making a user an
administrator.

See the link below on auditing. For starts it is a good idea to at least audit
account logon events and account management on domain controllers, logon events on
servers and domain workstations. --- Steve

http://www.microsoft.com/technet/security/guidance/secmod144.mspx

"Mail Man" <this4meonly@yahoo.com> wrote in message
news:2753502d.0407130101.6fbc8114@posting.google.com...
> Hi 2 Security concerns
> First:-
> How to make sure Even your Administrator
> can not alter and Log files and Audit Policy
> Second:-
> any good tool which can easily track changes in your Active Directory
> like user has been add to or remove from group
> permissions has been modified in Folders or Files
>
>
> Thanks 4 your Time& effort



Relevant Pages

  • Re: Monitor User Remotely.
    ... activity, auditing of process tracking on ... remotely via administrator share, and folder files have creation timestamps ... he can clear the security log. ... > Is there any way we can remotely monitor him, ...
    (microsoft.public.win2000.security)
  • Re: Unable to access Security Event Log Windows 2003 Stand alone
    ... The error that get loged is Windows error code: ... > administrator has the Manage auditing and security log right. ...
    (microsoft.public.security)
  • Re: Grey screen after login to 2003 TS
    ... Anything in the EventLog, especially the security log? ... I believe that this can happen when users have too few permissions on ... Run them as administrator (when no user ... MCSE,CCEA, Microsoft MVP - Terminal Server ...
    (microsoft.public.windows.terminal_services)
  • Re: Is there a way to query Security Event Log with Filter in C#?
    ... I am login as an administrator on my Win2k server. ... have over 55k of entries in Security log in Event Viewer. ... ManagementObjectSearcher mos = new ManagementObjectSearcher; ... foreach ) ...
    (microsoft.public.dotnet.languages.csharp)
  • Re: Server 2003 updates fail
    ... Some how the administrators was removed from Manage auditing and security log in the local security setting. ... > Please verify permissions on the following rights include the built-in ... I was log on as the administrator when getting ...
    (microsoft.public.windowsupdate)