Re: Object Access Audit Policy for a Domain



Either bad info in that book or it was misread.
Setting that policy and audit SACL(s) in a GPO linked to the
DCs OU will cause the DCs to cut audit events for accesses
made on the DCs to resources that are part of the DCs (that
meet the SACL criteria). That is all.
Setting the policy to audit object access in a GPO linked to
the domain will make that setting on all machines of the domain
to which it is applied. However, audit events are still controlled
by what SACLs say should be auditied (and most people do not
set SACLs using GPOs), and when the event messages are cut
to the log these are on the machine where triggered (where the
SACL'd resources are).

"Tom Glasser" <TomGlasser@xxxxxxxxxxxxxxxxxxxxxxxxx> wrote in message
news:0920CC9F-28D3-405D-8EEA-0BE3DD6BA024@xxxxxxxxxxxxxxxx
I am trying to figure out how Audit policies work. I got an "object
access"
policy to work on a local server (call it Server 1). Specified changes in
a
certain folder would show up in the Security Event Log of that server.
But
then I tried to implement the policy on the Domain Controller for the
entire
domain. A book I have says the folder events (on Server 1) should then
show
up in the Security Event Log on the Domain Controller. But I am not
seeing
the expected events getting logged. Any thoughts ??

Thanks,
Tom


.



Relevant Pages

  • Re: enabling Auditing on a shared folder for Windows SBS 2003
    ... I thought I had setup the auditing in the past but today ... Both object and policy need to be configured. ... You must perform a two-step process to enable the capability to audit ... Server 2003. ...
    (microsoft.public.windows.server.sbs)
  • Re: Object Access Audit Policy for a Domain
    ... Microsoft MVP (Windows Server: Security) ... It appears that my Domain policy change finally "percolated" down to my ... DCs OU will cause the DCs to cut audit events for accesses ...
    (microsoft.public.win2000.security)
  • Auditing File and folder deletion.
    ... Group policy select policy to edit ... Under Computer config, expand Windows settings, security ... local policies and audit policy. ... Should I look into the event viewer of the server or DC? ...
    (microsoft.public.windows.server.sbs)
  • RE: Granular audit configuration
    ... 'Success, Failure, No auditing' settings discussed in that document that I ... I'd like to only audit the successful object ... policy basically will audit every process you are running and fill up ... Download the Windows Server 2003 Security Guide from MS, ...
    (microsoft.public.windows.file_system)
  • Re: Difference between Security Audit of Active directory for Local Server and DC
    ... All AD operations are done in the DCs, so if you want to audit AD you must apply the policy to existing DCs and not membersers or others.... ... MCSE, MVP Directory Services ...
    (microsoft.public.windows.server.active_directory)