Re: DC Policy: just want to audit files, not set security

From: Roger Abell (mvpNOSpam_at_asu.edu)
Date: 03/17/05


Date: Thu, 17 Mar 2005 11:12:22 -0700


"Steven L Umbach" <n9rou@nospam-comcast.net> wrote in message
news:uxyD1txKFHA.656@TK2MSFTNGP14.phx.gbl...
> You are right Roger. I did not pick up on that part. Too bad file system
> permissions work that way where you can not use it to just enable
> uditing. --- Steve
>

Yes, it is too bad. I had never considered the case before.
For this person, the particular directory to root the auditing
makes it perhaps the most difficult case since there are so
very many subdirectories and individual files with explicitly
set, different permissions within the area. This makes setting
a DACL for the root of the area to be audited very complex.
I did not test, but if I recall, one can exempt subareas by
naming them in the template, setting them to not be changed;
the question then is, will the SACL for auditing still propagate
into those areas? Another test.

-- 
Roger
>
> "Roger Abell" <mvpNOSpam@asu.edu> wrote in message
> news:eHvKdkrKFHA.1172@TK2MSFTNGP12.phx.gbl...
> > You may a slightly misread the poster.
> >
> > I had never thought of using a SCE template File System
> > definition to deliver only Audit SACL to some storage
> > area, but I immediately thought I saw what the poster
> > was indicating.  Hence, I tried it out, and in fact if the
> > DACL part is left empty with only a SACL definition
> > provided, then upon application the DACL on the target
> > storage is changed.  That is, any explicit ACEs set on
> > the target are removed, and inheritance will be adjusted
> > (or not) depending on the settings choosen in the template.
> >
> > -- 
> > Roger
> > "Steven L Umbach" <n9rou@nospam-comcast.net> wrote in message
> > news:%23xDuJYpKFHA.2852@TK2MSFTNGP14.phx.gbl...
> >> They are separate. Be sure to limit auditing to just what is needed [
> >> write/delete maybe] as the security log will fill up very quickly if
you
> > try
> >> to audit everything. Just enabling auditing of object access will
> >> generate
> > a
> >> lot of events in the security log. Be sure to increase the size of the
> >> security log quite a bit to at least 20 MB to start.  --- Steve
> >>
> >> http://support.microsoft.com/default.aspx?scid=kb;en-us;301640  --- how
> >> to
> >> configure auditing.
> >>
> >>
> >> <-> wrote in message news:uv4XrRmKFHA.3500@TK2MSFTNGP14.phx.gbl...
> >> > Hello,
> >> >
> >> > I am being tasked with setting up auditing on the Windows directory
of
> > the
> >> > domain controllers via the Domain Controller Security Policy.  They
> > don't
> >> > want to touch permissions on it.  The thing is, the two seem linked
> >> > together.  If I leave the security permissions blank, on the security
> >> > field and just go to auditing, and select a group and what to audit,
> > will
> >> > I run the risk of removing all permissions to the Windows directory?
> >> >
> >>
> >>
> >
> >
>
>


Relevant Pages

  • Re: System Security Audits
    ... Security's Auditing Tools and security templates. ... > By system security audits I mean things like checking if computer ... > permissions (not too high or to say if user has restrictive ...
    (Pen-Test)
  • AW: ASP Dot Net Security Guidelines
    ... i have set up 2 dotnet server and did a pen-test of a dotnet server for ... i wouldn't focus so much on the file system permissions. ... ASP Dot Net Security Guidelines ...
    (Focus-Microsoft)
  • Re: Track a specific users share access activity?
    ... When you open the auditing tab in the Security dialog of the ... NTFS permissions in the properties of the storage area of ... just as if you were adding access permissions. ... Security) ...
    (microsoft.public.windows.server.security)
  • Re: Auditing
    ... Yes, as other MVP has stated, Auditing and NTFS permission are individual ... Each object has a set of security information, or security descriptor, ... In addition to containing permissions information, however, a security ...
    (microsoft.public.win2000.general)
  • Re: Have asp.net-hosted WinControl write to client
    ... that locking down the permissions... ... > Control to be able to write to the client's file system (or access a ... > CodeGroups. ... > operation not allowed by the security policy. ...
    (microsoft.public.dotnet.framework.aspnet.security)