Question

In: Computer Science

Let's look at the auditing system in Windows Server 2008. What are the characteristics? How do...

Let's look at the auditing system in Windows Server 2008. What are the characteristics? How do you set it up?

Solutions

Expert Solution

Let's start with what is Auditing.

Auditing keeps a record of things that have been modified in active directory.

Characteristics of Auditing System :

Windows Server 2008 makes auditing  easier and more comprehensive with following characteristics :

  • Global Object Access Auditing
  • Reason for access auditing
  • Advanced Audit Policy Configuration

1. Global Object Access Auditing : - By configuring Global Object Access Auditing policy settings, administrators can define computer system access control lists (SACLs) for various object types on computers for registry or file system. After configuring, SACL will be applied to all the objects of that type.

2. Reason for access auditing :- Access to objects are allowed or denied according to the ‘reason for access’ list—a list of Access Control Entries (ACE). Access. So administrators can easily identify the access controls that allowed or denied access to a particular object.

3. Advanced Audit Policy Configuration :- AD administrators can configure 53 audit policy settings using the domain Group Policy to perform more effective and simpler auditing. Broadly, administrators can audit events related to:

  • Account logon events
  • Account management events
  • Detailed tracking events
  • DS access events
  • Logon/logoff events
  • Object access events
  • Policy change events
  • Privilege use events
  • System events

Setting Up Auditing System in Windows Server

To implement Auditing System, we can implement controls in following places :

  • Global Audit Policy
  • System Access Control List
  • Schema

1. Global Audit Policy : In Server 2008 the Global Audit Policy is not on by default and must be enabled.

Step 1. Go to Start, Administrative Tools, and then click on Group Policy Management.

Step 2.

Navigate down through your Forest, to the Domains, then Domain Controllers and left click on Default Domain Controllers Policy.

You will get a warning that changes here will impact all other locations that the GPO is linked to. Click Ok.

Step 3. Right click on Default Domain Controllers Policy and then left click on Edit…

Step 4. Navigate under Computer Configurations → Policies → Windows Settings → Security Settings → Local Policies → Audit Policy

Step 5. Right click on Audit Directory Service Access, and then click Properties.

Step 6. Select Define these policy settings and then select Success. Click on Apply and then Ok.

That's it. Auditing has been set-up using Graphical User Interface (GUI).

To enable using command prompt, Enter following command in command prompt :

auditpol /set /subcategory:"directory service changes" /success:enable

2. System Access Control List (SACL) : The SACLs do most of the work in determining what gets auditing and what doesn't.

Step 1. Open Active Directory Computers and Users.

Step 2. Click on View and make sure that Advanced Features is enabled. If not left click on it to place a check next to it.

Step 3. Right click on any of the Organizational Units you want to audit; in our example I am going to audit Users. Then click

on Properties.

Step 4. In the Properties window click on Security.

Step 5. Next click on Advanced.

Step 6. Click the Auditing tab, then click Add.

Step 7. Under Enter the object name to select:, type in Authenticated Users and click Ok.

Step 8. In the next window under Apply onto:, select Descendant User Objects and under Access check the box for Successful next to Write all properties and click Ok.

Step 9. Click Ok until you are out of any dialog boxes.

Now that we have enabled auditing in a SACL.


Related Solutions

- What are the Windows Server threats and the security control?
- What are the Windows Server threats and the security control?
Active directory (AD) is arguably the most critical component of Windows Server 2008, certainly for larger...
Active directory (AD) is arguably the most critical component of Windows Server 2008, certainly for larger organizations. It enables corporations to manage and secure their resources from a single directory service and with a common interface—a very powerful tool. Because it is so powerful and offers so many features and capabilities, it sometimes can be complex to those looking at it for the first time. This week, we are going to learn about AD in detail, starting with the fundamentals....
Let's look at Tesla's profitability. What do the numbers say? Is Tesla profitable? Does it have...
Let's look at Tesla's profitability. What do the numbers say? Is Tesla profitable? Does it have a competitive advantage? Motivate your responses.
Let's look at the price of gasoline. What affects its price and how does that affect...
Let's look at the price of gasoline. What affects its price and how does that affect the sales of this product? If the price went up or down would that affect demand?
we are going to thoroughly discuss the business drivers for using Windows Server and how it...
we are going to thoroughly discuss the business drivers for using Windows Server and how it enables the business to be more efficient and effective (and therefore more successful and profitable). But first we have to understand what exactly Windows Server is. Let's start this discussion by defining what server actually means, what features are included in Windows Server, and how it is packaged and sold by Microsoft to different customers. After this, we'll get into the business requirements and...
Class, let's take a closer look at the what-if analysis tools of Excel. What are the...
Class, let's take a closer look at the what-if analysis tools of Excel. What are the different types of these tools? How are each different in terms of the number of input variables and the number of output calculations?
To do our analysis, let's look at one of the giants Please read these online resources....
To do our analysis, let's look at one of the giants Please read these online resources. Walmart. Read and explore these online resources pertaining to Walmart's history and Information System usage. The History of Walmart from their website 45 Years of Wal-Mart History: A Technology Time Line Information System Processes in the Wal-Mart Company Report (Assessment) write an informal paragraph or two on why you think Walmart has become so successful. Using chapter 7, "DOES IT MATTER," read, think about...
Windows Server 2016 - Configuring Advanced Storage Solutions - Discuss how the implementation of advanced storage...
Windows Server 2016 - Configuring Advanced Storage Solutions - Discuss how the implementation of advanced storage technology, such as that which is found in Windows Server 2016, may eliminate or reduce the need for larger storage hardware such as a SAN. Discuss the differences between Storage Replica and Data Deduplication. How are they complementary? How might they generate conflicting output?
Let's look at the popular sports apparel company Under Armour. What business are they in? What...
Let's look at the popular sports apparel company Under Armour. What business are they in? What is their business strategy?
Explain how folder and file auditing works within Microsoft Server 2016 and describe why a business...
Explain how folder and file auditing works within Microsoft Server 2016 and describe why a business may want to use it.
ADVERTISEMENT
ADVERTISEMENT
ADVERTISEMENT