Need for "Manage auditing and security log" User Right



We recently had some issues with installing updates that were resolved by
reassigning the "Manage auditing and security log" user right to
administrators.

The problem is that the organization I supports requires strict separation
of duties between administrators and security managers, and we need to
prevent administrators from tampering with auditing or security logs.

Is there a reason that this user right is specifically needed to install
Windows Updates? Is there a workaround? If not, can Microsoft consider
changing a future version of automatic updates to not require this particular
user right?

Thanks.
--
Jeffrey Harris, MCSE W2K and W2K3.
Please remove the '1's from the e-mail address before sending.
.



Relevant Pages

  • Re: Group Policy - Pushing out Software
    ... going to VNC into the computer, log on as the local Admin and do my thing". ... I would suspect that you are familiar with 'updates' via GPO. ... I know the way we access users machines using Remote Desktop ... > life easy for 2 administrators keeping 80 users machines updated. ...
    (microsoft.public.windows.server.active_directory)
  • Re: Group Policy - Pushing out Software
    ... I know the way we access users machines using Remote Desktop ... remotely, log on as them and do updates, without ... life easy for 2 administrators keeping 80 users machines updated. ... packages to specific profiles only. ...
    (microsoft.public.windows.server.active_directory)
  • Re: Logging IP address when Administrator logs in
    ... If you enable auditing of account logons in Domain Controller Security policy it will ... computers it will record a logon event in the security log of the computer that the ... administrators account on domain computers they need to manage. ...
    (microsoft.public.win2000.security)
  • Re: Loading MS Updates for clients
    ... We cannot setup these PC's as Administrators, ... > will not allow updates. ... You could consider implementing MS SUS, ... Microsoft MVP Scripting and WMI, ...
    (microsoft.public.windowsxp.security_admin)
  • Administrators Only.. under Windows 98 Se
    ... Administrators Only when we attempt to do Windows Updates. ... denote the computers network id.. ...
    (microsoft.public.windowsupdate)