Re: Auditing Account management events

From: Steven L Umbach (n9rou_at_n0-spam-for-me-comcast.net)
Date: 11/29/04


Date: Mon, 29 Nov 2004 03:09:48 GMT

If you have configured auditing of account management in Domain Controller
Security Policy, check the Local Security Policy of your domain controllers
to see if it shows as "effective" setting [ assuming W2K] for both of them
for auditing of account management for success and failure.. If it does and
you still do not see the events recorded, try clearing the security logs on
both domain controllers [saving them to file if need be] and increasing the
size of the security logs quite a bit to say at least 10 mb. By default the
security log is small and will stop recording events until manually cleared
after it fills up. --- Steve

"FEX" <anonymous@discussions.microsoft.com> wrote in message
news:0dfe01c4d5b7$116ca200$a501280a@phx.gbl...
> ummm curiosly ,that's what I'm doing I enabled auditing
> account management in the security policy on both domain
> controllers (DC-OU) ; However i can't see any event id how
> i told you .
>
>
>
>>-----Original Message-----
>>You don't need to do it that way and that would not work
> anyhow for what you
>>are looking for. Simply enable auditing of "account
> management" in the
>>security policy of the computer where you want to track
> these events. If you
>>are tracking events for domain users, enable auditing of
> account management
>>in Domain Controller Security Policy and view the
> security logs of the
>>domain controllers to find the related events. You can
> use the free Event
>>Comb tool from Microsoft to scan multiple computer logs
> in the domain from a
>>central point. See the link below for more details
> including explanation of
>>some Event ID's. --- Steve
>>
>>http://www.microsoft.com/technet/security/guidance/secmod1
> 44.mspx
>>
>>"fex" <anonymous@discussions.microsoft.com> wrote in
> message
>>news:0dcb01c4d5a6$35380e10$a501280a@phx.gbl...
>>>
>>> Hello,
>>>
>>> I've been auditing multiple events (System Events ,
>>> Policy Changes , Logon Events , but specially all events
>>> referents to Account management events like (User
> Account
>>> create, User Account Deleted , etc ) However , I applied
>>> the auditing to the default group everyone on Defaul
>>> Domain Controller Policy , to check specially all
> changes
>>> made by users with domain admin rights. But at this
> moment
>>> they are changing users -passwords - deleting users
> and -
>>> I don't receive any event id; for instance (ID:624-627-
> 630)
>>> at the moment they applied any change on the DC.
>>>
>>> I would like to know what is my misconfiguration or I
> need
>>> more configuartion or the default group it is not
> applied
>>> right way ?
>>>
>>> I will thanks any comment !!!
>>
>>
>>.
>>



Relevant Pages

  • Re: Auditing Questions
    ... By default Auditing is set on Domain Controllers GPO setting and thus ... You could enable auditing on your Domain level. ... > Does Auditing of events (example is Account Management ...
    (microsoft.public.win2000.active_directory)
  • Re: Monitoring/Audit of privileged accounts
    ... You can enable auditing of various events in the appropriate security policy. ... Auditing of account logons for instance on domain controllers via Domain Controller ...
    (microsoft.public.win2000.security)
  • Re: User get access denied error when prompted to change password adte Reset
    ... If you enable auditing of account management in the ... Domain Controller Security Policy, you may find useful info in the security ... make sure that the domain controllers do NOT have the ...
    (microsoft.public.win2000.security)
  • Re: Auditing Account management events
    ... account management in the security policy on both domain ... Simply enable auditing of "account ... >domain controllers to find the related events. ...
    (microsoft.public.win2000.group_policy)
  • Re: Many events in Security log
    ... If you do not want those events then disable auditing in "Domain Controller ... Security Policy" which is where you manage auditing for domain controllers. ... >> memory and cpu usage with Task Manager. ...
    (microsoft.public.windows.server.security)