Re: W2K3 R2 is not logging/auditing failure events



On May 2, 1:03 am, Florian Frommherz
<flor...@xxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx> wrote:

Try to configure the domain account audit settings at the Default Domain
Controllers OU as the domain controllers are the ones that will have to
audit those. If you did that, be sure to look at the eventlog of all
domain controllers in your organization, as only the domain controller
that proceeds the authentication request will write success/failure
messages into the eventlog. They do not get replicated.

Thanks for the reply... I thought I had did that.

I have a follow-up. Someone told me to install the Group Policy
Management Console. I did so and when I ran it, gpmc.msc did indeed
show the changes I made to the audit policy... BUT there is a column
titled "enforced" in the window and it displayed "no". When I went to
the domain server node, in the tree on the left-hand side of the
console, right clicked, and selected enforce, the audit settings I
specified started working.

So while everything is working as expected now, this makes me wonder,
if someone doesn't download and install gpmc, how does one turn
"enforce" on? Without seeing that enforce column reading "no", I
would have had no idea why the GPO settings I specified weren't
working.

Thanks!


.



Relevant Pages

  • Re: Auditing access to files and folders
    ... Audit policy on the DCs (default domain controllers policy) includes ... Maybe you're checking the wrong log viewer. ...
    (microsoft.public.win2000.security)
  • Re: I need a Step-by-Step to set up file deletion Auditing on SBS...
    ... Default Domain Controllers Policy. ... Right-click Domain Controllers, click Properties. ... Click Computer Configuration, double-click Windows Settings, double-click ... Audit Policy. ...
    (microsoft.public.windows.server.sbs)
  • Re: Windows 2000 Auditing Object Access
    ... One of the domain controllers is our File and Print server. ... server that I would like to audit files. ... In addition to that, several sub-categories under Security ... > you do it on an OU which contain your servers. ...
    (microsoft.public.windows.server.general)
  • Re: W2K3 R2 is not logging/auditing failure events
    ... Audit Account Logon Events, and selected audit success and failure. ... Try to configure the domain account audit settings at the Default Domain Controllers OU as the domain controllers are the ones that will have to audit those. ...
    (microsoft.public.windows.group_policy)
  • Re: What should be audited on a DC
    ... Generally for domain controllers you want to audit at least account ... change, and account management. ... Be sure to increase the size of your security logs quite a bit ...
    (microsoft.public.win2000.security)