Auditing / File Security

Auditing / File Security

Secure Home | Search | About
 Microsoft Applications Security    Post an article   get this group's latest topics as an RSS feed add this group's latest topics to your My MSN content add this group's latest topics to your My Yahoo content add this group's latest topics to your Google content
Subject Author Date
Auditing / File Security =?Utf-8?B?S2VsbHkgQXJtaXRhZ2U= 05-22-2008
Posted by =?Utf-8?B?S2VsbHkgQXJtaXRhZ2U= on May 22, 2008, 1:02 pm
If you were  Registered and logged in, you could reply and use other advanced thread options
Can anyone tell if it is possible (and if yes how?) to log or audit file
access. This is a large domain running 2003 AD with a mix of NT / 2000
servers.

The simple and basic scenario is as an example HR is a group all with access
to Folder X. Within Folder X there are some basic spreadsheets that all
these users can access. One of these users has either accidentally or
intentionally deleted one of these files. Retreiving the file from tape took
all of 3 minutes, but the powers that be would like to know which user it was
that deleted it. I have looked through the event viewer security logs and
cannot seem to find any reference to that file being accessed or deleted. Is
there an auditing feature on the DC that will enable me to check for such
things? If ther eis which is it, and what would it look like so I can
recognize it in the event viewer. I mean would the event specifically name
the file that was deleted?

USER A deleted FILE X? Any pointers tips or methods others use would be
great. It seems locking stuff down so that a small number of users are the
only ones with access to it, isn't enough these days.

HELP! :)

Posted by =?Utf-8?B?SG90c2F1Y2Ux?= on May 22, 2008, 5:58 pm
If you were  Registered and logged in, you could reply and use other advanced thread options
Yes

"Kelly Armitage" wrote:

> Can anyone tell if it is possible (and if yes how?) to log or audit file
> access. This is a large domain running 2003 AD with a mix of NT / 2000
> servers.
>
> The simple and basic scenario is as an example HR is a group all with access
> to Folder X. Within Folder X there are some basic spreadsheets that all
> these users can access. One of these users has either accidentally or
> intentionally deleted one of these files. Retreiving the file from tape took
> all of 3 minutes, but the powers that be would like to know which user it was
> that deleted it. I have looked through the event viewer security logs and
> cannot seem to find any reference to that file being accessed or deleted. Is
> there an auditing feature on the DC that will enable me to check for such
> things? If ther eis which is it, and what would it look like so I can
> recognize it in the event viewer. I mean would the event specifically name
> the file that was deleted?
>
> USER A deleted FILE X? Any pointers tips or methods others use would be
> great. It seems locking stuff down so that a small number of users are the
> only ones with access to it, isn't enough these days.
>
> HELP! :)

Posted by S. Pidgorny on May 25, 2008, 2:36 am
If you were  Registered and logged in, you could reply and use other advanced thread options
http://support.microsoft.com/kb/310399 (XP, equally applies to Windows 2003)
http://support.microsoft.com/kb/301640 (Windows 2000)
http://support.microsoft.com/kb/157238 (Windows NT)


--
Svyatoslav Pidgorny, MS MVP - Security, MCSE
-= F1 is the key =-

* http://sl.mvps.org * http://msmvps.com/blogs/sp *


> Can anyone tell if it is possible (and if yes how?) to log or audit file
> access. This is a large domain running 2003 AD with a mix of NT / 2000
> servers.
>
> The simple and basic scenario is as an example HR is a group all with
> access
> to Folder X. Within Folder X there are some basic spreadsheets that all
> these users can access. One of these users has either accidentally or
> intentionally deleted one of these files. Retreiving the file from tape
> took
> all of 3 minutes, but the powers that be would like to know which user it
> was
> that deleted it. I have looked through the event viewer security logs and
> cannot seem to find any reference to that file being accessed or deleted.
> Is
> there an auditing feature on the DC that will enable me to check for such
> things? If ther eis which is it, and what would it look like so I can
> recognize it in the event viewer. I mean would the event specifically
> name
> the file that was deleted?
>
> USER A deleted FILE X? Any pointers tips or methods others use would be
> great. It seems locking stuff down so that a small number of users are
> the
> only ones with access to it, isn't enough these days.
>
> HELP! :)



Similar ThreadsPosted
Security Event Log Performance for File and Folder Auditing January 26, 2007, 3:59 pm
Execute File Auditing on a File Share April 25, 2007, 11:46 pm
Auditing File deletion April 19, 2006, 3:26 am
Auditing Whom delete an file or folder. June 15, 2005, 3:06 am
Filtering the auditing of file access May 10, 2006, 4:20 am
Enable file auditing on many servers December 22, 2006, 2:21 pm
File auditing for MOVED files. May 30, 2008, 11:26 am
Enable Security Auditing using VBSCRIPT June 4, 2007, 7:27 pm
Auditing-- where?? and why ?? July 13, 2006, 3:12 am
Auditing December 20, 2006, 8:37 am

The site map in XML format XML site map

Contact Us | Privacy Policy