Re: Default Domain Controller Policy being overwritten

From: Chriss3 [MVP] (noSpamHere_at_chrisse.se)
Date: 08/30/04


Date: Mon, 30 Aug 2004 17:37:28 +0200

I'm not sure I understand the problem. do you meant audit are logged several
times from different GPOs?

-- 
Regards
Christoffer Andersson
Microsoft MVP - Directory Services
No email replies please - reply in the newsgroup
------------------------------------------------
http://www.chrisse.se - Active Directory Tips
"fnstrat2" <fnstrat2@discussions.microsoft.com> skrev i meddelandet
news:60AD08D4-89DC-47A9-9AEC-49A4D6AAFEBD@microsoft.com...
> I do have the event log size defined.  80000 kb's.  The problem is not
that
> the log file is not big enough, its more that everything is being written
to
> the log file and filling up in a few days.  The actual Policy is being
> rewritten to audit everything.  It's almost like I change the policy on
the
> server, it takes affect and works for a few minutes until the domain
> controller policy is reapplied and overwritten.  Like the server doesn't
> actually modify the group policy when I change it.
>
> "Chriss3 [MVP]" wrote:
>
> > Hello
> > You may need to define the Maximum event log size for the security logs,
> > Have a look at the page below.
> >
> >
http://www.microsoft.com/resources/documentation/WindowsServ/2003/all/techref/en-us/Default.asp?url=/resources/documentation/windowsServ/2003/all/techref/en-us/W2K3TR_sepol_event_set.asp
> >
> > -- 
> > Regards
> > Christoffer Andersson
> > Microsoft MVP - Directory Services
> >
> > No email replies please - reply in the newsgroup
> > ------------------------------------------------
> > http://www.chrisse.se - Active Directory Tips
> >
> > "fnstrat2" <fnstrat2@discussions.microsoft.com> skrev i meddelandet
> > news:7C512C3D-229A-4635-B189-1CFD485A8110@microsoft.com...
> > > The default domain controller policy is being overwritten every five
> > minutes
> > > when the gp updates the computer.  I noticed this because I started
> > getting
> > > messages every time I logged in saying the security log was full.
When I
> > > check the auditing options everything was set to audit success and
> > failure.
> > > I have tried resetting many times.  When I check the policy again it
is
> > > changed back to success and failure for all items.  This began
happening
> > > after our forest wide upgrade to windows 2003.  This problem is
happening
> > on
> > > the Schema Master.  I have run netdiag and dcdiag with no errors.
Also,
> > no
> > > errors relating to this in the event logs on either domain controller.
GP
> > > updates are applying successfully to the domain controllers.
> >
> >
> >


Relevant Pages

  • Re: Audit Deleting of files
    ... To configure an audit policy setting for a domain controller, ...
    (microsoft.public.win2000.security)
  • Re: security log filling/ audit policy being overwritten
    ... The audit configuration settings that you do not want enabled in Domain Controller ... Security Policy, may sure you set them to "no auditing" and not undefined. ...
    (microsoft.public.win2000.security)
  • Re: How do I log Failed Logon attempts
    ... You can configure auditing of account logon events using Group Policy. ... Click the Group Policy tab, click Default Domain Controller Policy, ... double-click Audit Policy. ... setting take effect only when the policy setting is propagated or applied to ...
    (microsoft.public.win2000.active_directory)
  • Re: How do I log Failed Logon attempts
    ... > You can configure auditing of account logon events using Group Policy. ... Click the Group Policy tab, click Default Domain Controller Policy, ... > double-click Audit Policy. ... > setting take effect only when the policy setting is propagated or applied ...
    (microsoft.public.win2000.active_directory)
  • Re: SBS 2003 Lost all the Security Policies.
    ... i didn't use dcgpofix i used another sbs 2003 premium has example and created the policies manually. ... I know that your Default Domain Controller Security Policy or Domain Security Policy it is empty. ... DCGPOFIX.EXE will restore the Default Domain Policy and the Default Domain Controller Policy to original default settings. ...
    (microsoft.public.windows.server.sbs)