Server refreshes its security policy with wrong values



Hello everybody,

I've got a new Windows Server 2003 R2 set up. The Audit Policy is set to
enable successful and failed logons. These settings are applied by me but
after some time, i.e. 8 AM the next morning the server logs the following
policy change.

Event ID: 612
User: NT AUTHORITY\SYSTEM
Audit Policy Change:
New Policy:
Success Failure
- - Logon/Logoff
- - Object Access
- - Privilege Use
- - Account Management
- - Policy Change
- + System
- - Detailed Tracking
- - Directory Service Access
- - Account Logon
Changed By:
User Name: ARWEN$
Domain Name: WG
Logon ID: (0x0,0x3E7)

This basically means that my previously applied Logon/Logoff audit was
turned off. I'm not sure which process triggered the update, it seems to
come from a system process as the User Name ARWEN$ (the server name)
suggests.

The server is a standalone server, AD is not installed. Does anyone know why
this happens and how I could fix the wrong policy update?

Best regards,

Alex
--
_______________________________________

Alexander Groß
Dipl.-Ing. (BA) für Informationstechnik
PLEASEAlexanderGrossREMOVETHIS@xxxxxx
http://www.it99.org/axl/
ICQ# 36765668
_______________________________________


.



Relevant Pages

  • Re: unable to enable "success" option of "Audit object access" und
    ... I have asked my AD administrator to define "Success" for my server ... place for the "Audit object access". ... > The server is getting audit policy from a GPO in Active Directory ...
    (microsoft.public.windows.server.security)
  • Re: Server refreshes its security policy with wrong values
    ... I've got a new Windows Server 2003 R2 set up. ... The Audit Policy is set to ... Audit Policy Change: ... this happens and how I could fix the wrong policy update? ...
    (microsoft.public.windows.server.security)
  • Re: Server refreshes its security policy with wrong values
    ... Is the server on a domain at all? ... If so it will be picking up the Default Domain policy at the least, ... Audit Policy Change: ...
    (microsoft.public.windows.server.security)
  • Re: How to Migrate Local User & Group Account to another Server
    ... I need to migrate the local user to the new server because the existing server have file permission, Owner & Audit policy with Local Account. ...
    (microsoft.public.win2000.security)
  • RE: Hacked Server
    ... What do your logs say? ... Failed logons is proof that Mr Hacker didn't logon. ... I doubt any hacker worth his salt would only shut down the server when ... sensitivity set to high (I had this same problem - my server shut down every ...
    (microsoft.public.windows.server.sbs)