How to perform auditing in Windows 2000 Server operating system?
Are you preparing for IT certification? With practice questions, study notes, interactive quizzes, tips and technical articles, uCertify PrepKits ensure that you get a solid grasp of core technical concepts to ace your certification exam in first attempt.
How to perform auditing in Windows 2000 Server operating system?
Rating:
In order to perform auditing in Windows 2000 Server operating system, the Group Policy snap-in must be used to enable Audit object access setting in an audit policy. Otherwise, an error is generated while setting auditing for an object (file/folder).
To add the Group Policy snap-in, the following steps should be taken:
- Open a new MMC console by typing MMC in the Run dialog box.
- In the Console menu, click Add/Remove Snap-in.
- In the Add/Remove Snap-in dialog box, click the Add button.
- In the Add Standalone Snap-in dialog box, select Group Policy and click the Add button. Click the Finish button in the Select Group Policy dialog box to perform auditing on the local computer, or click the Browse button to select the computer on which the auditing is to be performed.
- Close the Add Standalone Snap-in dialog box by clicking the Close button.
- Click the OK button to close the Add/Remove Snap-in dialog box.
- Save the new console under a name, through the Save As option of the Console menu. This new console is used for performing auditing in the chosen computer.
- Right-click the file/folder for which the auditing is to be performed.
- Click the Properties button, and then click the Security tab.
- Click the Advanced button, and click the Auditing tab.
- Depending upon the type of auditing to be performed, any one of the following three cases is applicable:
- In order to perform auditing for a new user/group, the procedure below is followed:
- Click the Add button. In the Select User, Computer, or Group dialog box, select the username or group for which the auditing is to be performed.
- Click the OK button to open the Auditing Entry dialog box.
- To change the audit settings for an existing user/group, click the user/group, and then click View/Edit.
- For removing an existing user/group, click the username/group, and click the Remove button.
- In order to perform auditing for a new user/group, the procedure below is followed:
- Under the Access field, click Successful or Failed for auditing success or failure for the corresponding event, respectively. Both success and failure audits can also be performed, depending upon the requirements.
- In Control Panel, double-click Administrative Tools.
- In the Administrative Tools window, double-click Local Security Policy.
- In the Local Security Settings window that pops up, expand the Local Policies tree.
- Double-click Audit Policy.
- In the Local Security Settings window, double-click the auditing policy that is to be enabled or disabled.
- Under Audit these attempts, click Success or Failure for auditing success or failed attempts against the events, respectively.
- Click the OK button.
Rating:
Was this information helpful?
Other articles
- What is TRACEROUTE utility?
- What is Digest authentication?
- Why is IMAP4 protocol preferred over POP3 protocol?
- What is RAID-5 volume?
- What is NFS?
