RE: Enabling an audit policy on my DC's

Tech Tip: Click here to run a free scan for Windows Errors and optimize PC performance



Hi Harrison,

The bottom of the article outlined: The policy change will not take place
immediately. Active Directory domain controllers automatically check for
policy changes to domain controller policy every five minutes. Replication
intervals also must be considered for the policy to propagate throughout
all domain controllers in the organization.

If the group policy still not applied.
1. run gpupdate/force to see the results
2. go back to check if you have edited the policy correctly.

Best regards,

Vincent Xu
Microsoft Online Partner Support

======================================================
Get Secure! - www.microsoft.com/security
======================================================
When responding to posts, please "Reply to Group" via your newsreader so
that others
may learn and benefit from this issue.
======================================================
This posting is provided "AS IS" with no warranties,and confers no rights.
======================================================



--------------------
From: "Harrison Midkiff" <HMidkiff@xxxxxxxxxx>
Subject: Enabling an audit policy on my DC's
Date: Sun, 7 May 2006 15:16:06 -0400
Lines: 18
X-Priority: 3
X-MSMail-Priority: Normal
X-Newsreader: Microsoft Outlook Express 6.00.2900.2869
X-RFC2646: Format=Flowed; Original
X-MimeOLE: Produced By Microsoft MimeOLE V6.00.2900.2869
Message-ID: <uWUByqgcGHA.3348@xxxxxxxxxxxxxxxxxxxx>
Newsgroups: microsoft.public.win2000.group_policy
NNTP-Posting-Host: 117-120.8-67.tampabay.res.rr.com 67.8.120.117
Path: TK2MSFTNGXA01.phx.gbl!TK2MSFTNGP01.phx.gbl!TK2MSFTNGP03.phx.gbl
Xref: TK2MSFTNGXA01.phx.gbl microsoft.public.win2000.group_policy:39811
X-Tomcat-NG: microsoft.public.win2000.group_policy

Hello:

I am trying to enable auditing on my DC's. My setup is standard. All my
servers are in the "Domain Controllers" OU. I edited the "Default Domain
Controllers Policy" under "Computer Configuration\Windows
Settings\Security
Settings\Local Policies\Audit Policy". I enabled "Audit Account
Management"
and a few others. When I looked in the Security log for the events which
should be generated by this setting they do not appear. I did a
"gpresult
/v" and on the DC's are applying the "Default Domain Controllers Policy".

I followed TechNet doc 314977 "How to enable Active Directory access
auditing in Windows 2000" as a guide.

I am a bit confused why I am not getting the auditing? Does anyone have
any
suggestions? Is there something I missed?
Harrison Midkiff




.



Relevant Pages

  • Re: Default Domain password policy issue
    ... The domain controllers are members of authenticated users. ... as for applied Group Policy objects for computer settings. ... Policy replication/version problems. ... The settings in this GPO can only apply to the following groups, users, ...
    (microsoft.public.windows.group_policy)
  • Re: Blocking port scans on local network
    ... You can implement enumeration of SAM accounts and shares with probably no ... on domain controllers via Domain Controller Security Policy depending of ... domain computer that has a "require" ipsec policy assigned to it. ... between domain computers and domain controllers as the domain controllers ...
    (microsoft.public.win2000.security)
  • RE: Account Lockout Policy
    ... he didn't say that the policy would be *linked* at ... the Domain Controllers OU, just that the domain password policy would apply ... the Domain Controllers OU will still use the password policy that is defined ... they still utilize the domain-level account settings, because, again, the ...
    (Focus-Microsoft)
  • Re: Blocking port scans on local network
    ... > additional restrictions for anonymous connections in this security guide. ... > do not recommend applying ipsec policy wide scale without some testing of ... > between domain computers and domain controllers as the domain controllers ...
    (microsoft.public.win2000.security)
  • domain users cant logon locally
    ... This is probably caused by the fact that your Windows 2000 ... To find this setting right click the DOmain Controllers OU ... Policy tab, verify that the Default Domain Controllers ... >I have recently installed a new windows 2000 server. ...
    (microsoft.public.win2000.security)