Can't get "Audit object access" to work.


hello,

i want see changing ntfs security properties on of file servers. came across couple documents on technet explained use “audit object access” option. tried set these technet documents guidline.

what did
- created new ou in our windows server 2008 r2 active directory.

- created , linked new gpo new ou.
- edit new gpo:
       computer configuration/policies/windows settings/security settings/local policies/audit policy
              
defined policy “audit object access” success , failure checked.
- put test file server in ou.
- ran gpupdate /force.
- checked if computer gpo applied (it was).
- checked in local policy if settings applied (it was).

on test file server
- created temporary directory test.
- went auditing tab of directory (properties/security/advanced/auditing).
- added “everyone” “change permissions” successful , failed checked.
             checked “apply auditing entries objects and/or containers within
             container”.

what expected see…
when changes (or tries to) permissions on test directory expected see 560 and/or 562 events in event viewer. sadly don’t…

what doing wrong?

best regard,

sjoerd

hi sjoerd,

 

these events should recorded on file server. before go further, confirm os version running on file server. event id in windows server 2003 , windows server 2008 may different.

 

if it’s windows server 2008 or windows server 2008 r2, windows logs event 4670 when changes access control list on object.

 

4670

permissions on object changed.

 

please check if can find event 4670 on file server.

 

regards,

bruce



Windows Server  >  Security



Comments

Popular posts from this blog

CRL Revocation always failed

Failed to query the results of bpa xpath

0x300000d errors in Microsoft Remote Desktop client