Re: DC Policy: just want to audit files, not set security

From: Steven L Umbach (n9rou_at_nospam-comcast.net)
Date: 03/17/05


Date: Thu, 17 Mar 2005 12:03:51 -0600

You are right Roger. I did not pick up on that part. Too bad file system
permissions work that way where you can not use it to just enable
uditing. --- Steve

"Roger Abell" <mvpNOSpam@asu.edu> wrote in message
news:eHvKdkrKFHA.1172@TK2MSFTNGP12.phx.gbl...
> You may a slightly misread the poster.
>
> I had never thought of using a SCE template File System
> definition to deliver only Audit SACL to some storage
> area, but I immediately thought I saw what the poster
> was indicating. Hence, I tried it out, and in fact if the
> DACL part is left empty with only a SACL definition
> provided, then upon application the DACL on the target
> storage is changed. That is, any explicit ACEs set on
> the target are removed, and inheritance will be adjusted
> (or not) depending on the settings choosen in the template.
>
> --
> Roger
> "Steven L Umbach" <n9rou@nospam-comcast.net> wrote in message
> news:%23xDuJYpKFHA.2852@TK2MSFTNGP14.phx.gbl...
>> They are separate. Be sure to limit auditing to just what is needed [
>> write/delete maybe] as the security log will fill up very quickly if you
> try
>> to audit everything. Just enabling auditing of object access will
>> generate
> a
>> lot of events in the security log. Be sure to increase the size of the
>> security log quite a bit to at least 20 MB to start. --- Steve
>>
>> http://support.microsoft.com/default.aspx?scid=kb;en-us;301640 --- how
>> to
>> configure auditing.
>>
>>
>> <-> wrote in message news:uv4XrRmKFHA.3500@TK2MSFTNGP14.phx.gbl...
>> > Hello,
>> >
>> > I am being tasked with setting up auditing on the Windows directory of
> the
>> > domain controllers via the Domain Controller Security Policy. They
> don't
>> > want to touch permissions on it. The thing is, the two seem linked
>> > together. If I leave the security permissions blank, on the security
>> > field and just go to auditing, and select a group and what to audit,
> will
>> > I run the risk of removing all permissions to the Windows directory?
>> >
>>
>>
>
>



Relevant Pages

  • Re: xPC Target File I/O
    ... If you open up xpc Explorer and connect to your target, ... do you see anything under the 'File System' entry in the tree? ... 32MB FlashRAM disk. ...
    (comp.soft-sys.matlab)
  • Re: Checking consistency of drive D (long)
    ... Roger, I am having the same problem. ... To determine whether the volume is corrupt, ... In this case, repair the file system. ... >> harddrives on same controller and formatted as NTFS file ...
    (microsoft.public.windowsxp.hardware)
  • [ANN] Building Embedded Systems with Linux and Open Source
    ... build and boot a Linux target with an initial RAM disk; ... and open source software to craft embedded systems. ... reconfigure for an NFS-mounted root file system, ...
    (comp.os.linux.announce)
  • Re: why host shell cant access target file system?
    ... target to have onboard flash just for the sake of running few scripts. ... The ROMFS that's being discussed here is a RAM based, ... it has the drawback that the file system contents are ...
    (comp.os.vxworks)
  • Re: Insert.... Select From... question
    ... The target table has a primary key but it isnt an identity ... You did screw up the schema! ... SQL is a set oriented language, not a sequential file system. ... Now if you want to start over and do it right, with a proper data model ...
    (microsoft.public.sqlserver.programming)