Windows Server 2003 in a Nutshell
| Auditing Tasks |
Before you can designate which objects to audit, you have to configure auditing. This section describes how to do this and related auditing tasks.
Configure Audit Policy
Audit policies can be configured on computers in several ways. For example, to configure auditing for standalone servers and workstations belonging to a workgroup:
Administrative Tools
For computers belonging to a domain, you can do the same for each machine by using the Domain Controller Security Policy on domain controllers and the Local Security Policy on member servers and workstations. Alternatively, you can use Group Policy to configure auditing at the domain, OU, or site level For example, to configure an audit policy for a domain by editing an existing GPO, do the following:
Administrative Tools
Configure Security Options for Auditing
The three security options for auditing discussed in AuditingConcepts are configured as follows :
Administrative Tools
All three are disabled by default.
|
Audit Active Directory Objects
First, configure your audit policy to enable Success and/or Failure auditing for Directory service access (see Configure Audit Policy earlier in this section) and then specify which AD objects you want to audit. For example, to audit access to the Users container in the mtit.local domain:
Open Active Directory Users and Computers
|
Audit Filesystem Objects
First, configure your audit policy to enable Success and/or Failure auditing for Object access (see Configure Audit Policy earlier in this section) and then specify which files or folders you want to audit (these must be on an NTFS volume). For example, if you want to audit access to the file C:\hello.txt , you can use Windows Explorer to enable auditing of the file as follows:
Windows Explorer
Configuring auditing on many individual files is a lot of work. It's almost always better to configure auditing on folders instead. You can specify that the audit settings be applied to:
-
This folder only
-
This folder, subfolders , and files
-
This folder and subfolders
-
This folder and files
-
Subfolders and files only
-
Subfolders only
-
Files only
The default is to pass audit settings down the entire subtree of files and subfolders beneath the folder you are configuring, which is the typical choice.
Enable Auditing of Printers
To enable auditing of printers:
Start
Printer access can be audited for documents only, for the printer only, or for both.