Re: Setting Audit Permissions Differently for Each User



Hi Will,

Jesper is quite correct in his response.

You may be able to accomplish this objective more simply than
defining a group with all accounts except System however, if
your users are members of Users (or Domain Users and hence
of Users).

I notice that System does not have Users in its token but does
have Authenticated Users, Administrators, and Everyone.

Now, for this to work, you would need to have Interactive and
Authenticated Users removed from Users (I routinely remove
Interactive and Authenticated Users from Users anyway).

So, if you just either made sure that each individual admin account
was member of Users (or Domain Users), or if you defined a group
that mirrored Administrators, and used these in place of Everyone
then you would not be auditing for System via those and could
avoid the duplications Jesper indicated.

Roger
"Will" <westes-usc@xxxxxxxxxxxxxx> wrote in message
news:J_adnbLFOJjLHQzYnZ2dnUVZ_vipnZ2d@xxxxxxxxxxxxxxx
So far I have used the auditing features in NTFS by specifying rules for
reserved user Everyone, just to make the rules simple to specify. Is
there a way I could specify one rule for SYSTEM, another rule for every
other user? In other words, if you have multiple users or groups in
your
audit list, and then a catch all for Everyone, how does Windows process
those rules?

--
Will




.



Relevant Pages

  • Re: Setting Audit Permissions Differently for Each User
    ... Jesper is quite correct in his response. ... defining a group with all accounts except System however, ... Authenticated Users removed from Users (I routinely remove ... Controllers, Computers from Trusted domains, etc. ...
    (microsoft.public.windows.server.security)
  • RE: XP Home Password Prompted but None Set
    ... Thank you, Jesper. ... anything at the password prompt on the blue screen, it gives me the "did you ... I have XP Home and I never set a password for any of my accounts ... if I switch users or if the system hibernates all of a sudden the ...
    (microsoft.public.windowsxp.security_admin)
  • Re: Repost: Local logon and Network Access settings
    ... think require network login since they are over the wire do in fact ... In the default situation, Authenticated Users ... is a member of User on a member machine, and, Users are granted ... user accounts that should be allowed to log into the machines in SomeOU. ...
    (microsoft.public.windows.group_policy)
  • Re: Auditing ?
    ... Authenticated Users contains all accounts, of people and machines, that ... and Administrators (which will exclude local accounts and machines). ... > I have disable the GPO object to audit system events. ...
    (microsoft.public.win2000.security)
  • RE: GPO not being applied to OU
    ... accounts as well. ... member of the authenticated users group. ... "visiting users" from another OU would have permission to have the GPO ... the users OU...only user settings will affect that OU and its users, ...
    (microsoft.public.windows.group_policy)