Re: DNS entry deletion tracking




"Brendon B" <BrendonB@xxxxxxxxxxxxxxxxxxxxxxxxx> wrote in message
news:51F45B04-C561-47AF-BF80-6FC8C86BF275@xxxxxxxxxxxxxxxx
Hi Martin

That may be the case

We have the following auditing in place on our Domain controllers:

Audit account logon events No auditing
Audit account management Success, Failure
Audit directory service access No auditing

IF this auditing were enabled you
COULD enable auditing on AD objects you wish to monitor
and get the audit records in the security log ( it can get big
and out of control rapidly however.)


Audit logon events Success, Failure
Audit object access Success, Failure
Audit policy change Success
Audit privilege use Success
Audit process tracking Success
Audit system events Success, Failure

Would this deletion have been covered in one of the categories above?

No. And even if you had enabled (success) for the directory
service object access then you would still have needed to enable
the auditing ACLs (like NTFS permissions) on the actual objects
you wished to monitor.

If so, what event would I have to look for?

Security event log, object access entries for (primarily) success.



.



Relevant Pages

  • Re: Auditing Privilege Use - failure only but still get Success
    ... Success only (applies to remote access, ... Audit account management: No Auditing ... Audit privilege use: No Auditing ...
    (microsoft.public.win2000.group_policy)
  • HELP - File Auditing
    ... not automatically trigger any new "object access" audit ... individual objects for audit events to be logged. ... To enable auditing on a file/directory do the following: ... GPEDIT.msc in that server, ...
    (microsoft.public.win2000.security)
  • Re: How to determine who changed permissions on a directory?
    ... Audit Account Logon events - Success, Failure ... Computer: SERVER1 ...
    (microsoft.public.security)
  • RE: Auditing Features
    ... >Subject: Auditing Features ... >descriptions on auditing Object Access and what it really ... The Audit object access setting determines whether to audit the event of a ... Failure audits generate an audit entry when a user unsuccessfully attempts ...
    (microsoft.public.win2000.security)
  • Re: How to determine who changed permissions on a directory?
    ... if your resources are ACL's only with resource groups ... Audit Account Logon events - Success, Failure ...
    (microsoft.public.security)

Loading