Re: Setting Audit Permissions Differently for Each User



Hi Will,

Jesper is quite correct in his response.

You may be able to accomplish this objective more simply than
defining a group with all accounts except System however, if
your users are members of Users (or Domain Users and hence
of Users).

I notice that System does not have Users in its token but does
have Authenticated Users, Administrators, and Everyone.

Now, for this to work, you would need to have Interactive and
Authenticated Users removed from Users (I routinely remove
Interactive and Authenticated Users from Users anyway).

So, if you just either made sure that each individual admin account
was member of Users (or Domain Users), or if you defined a group
that mirrored Administrators, and used these in place of Everyone
then you would not be auditing for System via those and could
avoid the duplications Jesper indicated.

Roger
"Will" <westes-usc@xxxxxxxxxxxxxx> wrote in message
news:J_adnbLFOJjLHQzYnZ2dnUVZ_vipnZ2d@xxxxxxxxxxxxxxx
So far I have used the auditing features in NTFS by specifying rules for
reserved user Everyone, just to make the rules simple to specify. Is
there a way I could specify one rule for SYSTEM, another rule for every
other user? In other words, if you have multiple users or groups in
your
audit list, and then a catch all for Everyone, how does Windows process
those rules?

--
Will




.



Relevant Pages

  • Re: Setting Audit Permissions Differently for Each User
    ... Jesper is quite correct in his response. ... defining a group with all accounts except System however, ... Authenticated Users removed from Users (I routinely remove ... Controllers, Computers from Trusted domains, etc. ...
    (microsoft.public.windows.server.security)
  • RE: XP Home Password Prompted but None Set
    ... Thank you, Jesper. ... anything at the password prompt on the blue screen, it gives me the "did you ... I have XP Home and I never set a password for any of my accounts ... if I switch users or if the system hibernates all of a sudden the ...
    (microsoft.public.windowsxp.security_admin)
  • Re: Repost: Local logon and Network Access settings
    ... think require network login since they are over the wire do in fact ... In the default situation, Authenticated Users ... is a member of User on a member machine, and, Users are granted ... user accounts that should be allowed to log into the machines in SomeOU. ...
    (microsoft.public.windows.group_policy)
  • Re: windows new users?
    ... the 2 accounts that I mentioned abv is some username ... "userS" in the account name and they are security principal identifier ... those without the Authenticated Users group will hit into a brick wall! ...
    (microsoft.public.windowsxp.setup_deployment)
  • Re: windows new users?
    ... doesn't use any accounts at all. ... To login and fulfill the remote assistance, ... those without the Authenticated Users group will hit into a brick wall! ...
    (microsoft.public.windowsxp.setup_deployment)