RE: Repost: Security Question

Tech-Archive recommends: Repair Windows Errors & Optimize Windows Performance

From: Charles Yang [MSFT] (v-chayan_at_online.microsoft.com)
Date: 01/20/05


Date: Thu, 20 Jan 2005 12:20:50 GMT

Hi Marcia,
 
Thank you for posting here.
 
>From the description, I understand that you met a question that in event
538 in security audit log. It is an expected behavior in SBS2003, $ mean it
is the computer name, In SBS 2003, the full security audit is enabled by
default so that you are able to monitor the server and network access
events if needed. It's normal that many logon/logoff events are logged
because one logon/logoff procedure can generate several events. The
logon/logoff procedures are always performed by service startup/shutdown,
shared file accessing, network accessing, users' logon/logoff etc. Event
540 indicates a successful logon; event 538 indicates a successful logoff
and event 576 indicates a successful special privilege assign. You may
safely ignore these events.
 

In addition, if you do want to stop these events, you can turn off Success
logon auditing, although it is not recommended. To do so:
 
1. Click Start, click Run, type "gpmc.msc" and click OK.
2. Expand Domains -> your domain -> Domain Controllers.
3. Right-click Small Business Server Auditing Policy and click Edit.
4. Expand Computer Configuration -> Windows Settings -> Security Settings
-> Local Policies -> Audit Policy.
5. In the right pane, double-click Audit logon events and clear the Success
check box. Click OK.
6. Run "gpupdate /force".

 
More information:
 
Securing Your Windows Small Business Server 2003 Network
http://www.microsoft.com/downloads/details.aspx?familyid=f62b2722-267c-4642-
b287-c31115ef10a4&displaylang=en
 
Account Passwords and Policies
http://www.microsoft.com/technet/prodtechnol/windowsserver2003/technologies/
security/bpactlck.mspx
 
Threats and Countermeasures: Security Settings in Windows Server 2003 and
Windows XP
http://www.microsoft.com/downloads/details.aspx?FamilyId=1B6ACF93-147A-4481-
9346-F93A4081EEA8&displaylang=en
 
 
I hope the above information is useful to you, if you have any questions
please feel free and let me know.
 
Have a nice day!
 
 
 
Charles Yang
Online Partner Support
Partner Support Group
Microsoft Global Technical Support Center
 Mailto: v-chayan@microsoft.com

Sincerely,

Charles Yang (MFST)

Microsoft Partner Online Support

Get Secure! - www.microsoft.com/security
====================================================
When responding to posts, please "Reply to Group" via your newsreader

so that others may learn and benefit from your issue.
====================================================
This posting is provided "AS IS" with no warranties, and confers no rights.



Relevant Pages

  • RE: Security audit & Domain Controller security
    ... the full security audit is enabled by default so that you are ... Event 540 indicates a successful ... Right-click Small Business Server Auditing Policy and click Edit. ...
    (microsoft.public.windows.server.sbs)
  • [Full-disclosure] SSANZ - Server Systems Administration NZ.
    ... Security Hardening & Security Installs/tweaks. ... What is involved in a Full Security Audit? ... csf -a 125.238.144.110 ...
    (Full-Disclosure)
  • RE: True definition of Intrusion Prevention
    ... when protecting a production Unix/Apache environment? ... As with any security tool, what ... network security is a difficult problem that is unique to ... Proper planning is the key to having a successful ...
    (Focus-IDS)
  • Update #823559
    ... Installation History ... Successful Sunday, October 05, 2003 823559: Security ...
    (microsoft.public.windowsxp.security_admin)