Computer Problems? Computing.Net has over 1,000,000 posts about all things technology related! Over 90% answered within 24 hours! Click here to start participating now! Also, be sure to check out the New User Guide.
Security Auditing
Name: Jeremy Date: August 7, 2002 at 21:56:19 Pacific
Comment:
I accidentally audited "logon events" instead of "account logon events" in the default domain policy and now it audits every system logon event and I cant switch it back. I set up domain auditing the way I want it and when I do a secedit /refreshpolicy machine_policy /enforce it tells me "Group policy propagation from the domain has been initiated for this computer.........." but it never refreshes. I've looked in the event log and there is no entry saying anything has changed. I've even waited 2 days for it to refresh itself and it never does. There is no auditing set for the local machine or the default domain controller policy. The only auditing defined is "audit account managment" and "audit directory service access". should I set these options on the default domain controller policy instead of the default domain policy? All I want to do is audit when specific groups log on or off of the domain, that why I checked the audit directory service access. Someone please help, this is really causing a painful headache
Name: Jeremy Date: August 7, 2002 at 22:04:01 Pacific
Reply:
One more thing, when I look at the local machine audit policy of the server under local settings everything is set to no auditing. In the colum named "effective settings" audit logon events is set to success and failure, even though its set to no auditing under the default domain and domain controller policies.
Summary: Hi, I have problem on How to enable the Security Auditing in Win2K. I already created the Group Policy Snap-In using MMC, but the problem is I can't trail users who deleted the file or changed somethi...
Summary: Is there any free and/or commerical products which allow you to Audit a W2K File Server and provide friendly reports about which users have access to which folders ? I've tried using PERMS.EXE from th...
Summary: I am auditing users on several notebooks with removeable hard drives. Some of these notebooks have LAN Accounts and some do not. The specific problem I am having is capturing user logoff events(538)...