Can't get "Audit object access" to work.
hello,
i want see changing ntfs security properties on of file servers. came across couple documents on technet explained use “audit object access” option. tried set these technet documents guidline.
what did
- created new ou in our windows server 2008 r2 active directory.
- created , linked new gpo new ou.
- edit new gpo:
computer configuration/policies/windows settings/security settings/local policies/audit policy
defined policy “audit object access” success , failure checked.
- put test file server in ou.
- ran gpupdate /force.
- checked if computer gpo applied (it was).
- checked in local policy if settings applied (it was).
on test file server
- created temporary directory test.
- went auditing tab of directory (properties/security/advanced/auditing).
- added “everyone” “change permissions” successful , failed checked.
checked “apply auditing entries objects and/or containers within
container”.
what expected see…
when changes (or tries to) permissions on test directory expected see 560 and/or 562 events in event viewer. sadly don’t…
what doing wrong?
best regard,
sjoerd
hi sjoerd,
these events should recorded on file server. before go further, confirm os version running on file server. event id in windows server 2003 , windows server 2008 may different.
if it’s windows server 2008 or windows server 2008 r2, windows logs event 4670 when changes access control list on object.
4670 | permissions on object changed. |
please check if can find event 4670 on file server.
regards,
bruce
Windows Server > Security
Comments
Post a Comment