Re: Setting Audit Permissions Differently for Each User
- From: "Will" <westes-usc@xxxxxxxxxxxxxx>
- Date: Sat, 30 Dec 2006 18:16:53 -0800
"Roger Abell [MVP]" <mvpNoSpam@xxxxxxx> wrote in message
news:OwHUSO%23KHHA.3560@xxxxxxxxxxxxxxxxxxxxxxx
Hi Will,
Jesper is quite correct in his response.
You may be able to accomplish this objective more simply than
defining a group with all accounts except System however, if
your users are members of Users (or Domain Users and hence
of Users).
I notice that System does not have Users in its token but does
have Authenticated Users, Administrators, and Everyone.
How do you enumerate the user groups that SYSTEM belongs to?
Now, for this to work, you would need to have Interactive and
Authenticated Users removed from Users (I routinely remove
Interactive and Authenticated Users from Users anyway).
So, if you just either made sure that each individual admin account
was member of Users (or Domain Users), or if you defined a group
that mirrored Administrators, and used these in place of Everyone
then you would not be auditing for System via those and could
avoid the duplications Jesper indicated.
I've never been crazy about Authenticated Users as a concept as it embraces
too many totally different things and just makes it harder to figure out
what is or is not controlled in an ACL.
The only problem in your approach is you would need to think through what
other kinds of access were previously covered by Authenticated Users and
provide for those another way. For example, Domain Computers, Domain
Controllers, Computers from Trusted domains, etc.
It would sure be nice if Microsoft would publish a way to build a
comprehensive list of all entities that might interact with a computer so we
could control at that level when we want to.
--
Will
.
- Follow-Ups:
- Re: Setting Audit Permissions Differently for Each User
- From: Roger Abell [MVP]
- Re: Setting Audit Permissions Differently for Each User
- References:
- Setting Audit Permissions Differently for Each User
- From: Will
- Re: Setting Audit Permissions Differently for Each User
- From: Roger Abell [MVP]
- Setting Audit Permissions Differently for Each User
- Prev by Date: Re: Setting Audit Permissions Differently for Each User
- Next by Date: Command Line Utility for Audit List?
- Previous by thread: Re: Setting Audit Permissions Differently for Each User
- Next by thread: Re: Setting Audit Permissions Differently for Each User
- Index(es):
Relevant Pages
|