Re: SDDL confirmation -- Set event log security for the domain
- From: "SecAdmin" <SecAdmin@xxxxxxxxxxxxxxxxxxxxxxxxx>
- Date: Thu, 16 Jun 2005 13:45:04 -0700
Do you know if there is anything in the delegation options that allow
granting read access to event logs only on a particular domain controller?
"Joe Richards [MVP]" wrote:
> If you set the SD via a direct registry mod it will only impact the machine that
> you make the change on. If you implement via a GPO it will apply to any machines
> that are impacted by that GPO.
>
> joe
>
> --
> Joe Richards Microsoft MVP Windows Server Directory Services
> www.joeware.net
>
>
> ITConsultant wrote:
> > Article 323076 talks about registry settings to allow "domain" access to
> > security logs for a particular group. I just want to confirm that if I make a
> > change on one domain controller that it will propagate to the other domain
> > controllers in the same domain. But reading more closely leads me to believe
> > that this change is static and will only affect one "local" domain controller.
> >
> > Can one of you MCP's or other qualified individuals respond?
> >
> > Thanks,
> >
> > Roy
> >
> > http://support.microsoft.com/default.aspx?scid=kb;en-us;323076#XSLTH3157121122120121120120
> >
> >
>
.
- Follow-Ups:
- Re: SDDL confirmation -- Set event log security for the domain
- From: Joe Richards [MVP]
- Re: SDDL confirmation -- Set event log security for the domain
- Prev by Date: Re: AzMan & ADAM
- Next by Date: Re: Controlling object visibility
- Previous by thread: Windows 2000 DC's bringing in 2003 DC's
- Next by thread: Re: SDDL confirmation -- Set event log security for the domain
- Index(es):
Relevant Pages
|