Small Business Server Support, Server Support Services, Online Server Support

  • Subscribe to our RSS feed.
  • Twitter
  • StumbleUpon
  • Reddit
  • Facebook
  • Digg

Thursday, 12 February 2009

Windows Server 2008: Active Directory Domain Services Auditing Capabilities Explained

Posted on 06:29 by Unknown
Active Directory Domain Services Auditing has remained fairly consistent since the first release of Active Directory in Windows 2000 Server. However, Microsoft has introduced new Active Directory Domain Services auditing capabilities in Windows Server 2008. Active Directory Domain Services auditing in Windows Server 2008 provide more granular auditing capabilities and more control.

This article takes a deeper look at the new Active Directory Domain Services auditing capabilities in Windows Server 2008.

New Default Auditing Settings in Group Policy

Windows 2000 Server and Windows Server 2003 enabled auditing for a number of policies by default. However, Windows Server 2008 does not define these global audit settings by default. These settings are instead defined by using the new auditing subcategories. This may seem as though auditing is not configured by default, however this is not the case. The configuration of the global audit settings is inherited by the subcategories below that global audit setting. Therefore, Microsoft chose to configure specific subcategories by default, which is covered in the next section.

New Auditing Subcategories

As previously mentioned, Windows Server 2008 introduces auditing subcategories. The following table shows the subcategories below each global audit setting, as well as the default configuration for each audit subcategory.


Global Audit Setting

Subcategory

Default Setting

Audit Account Logon Events

Kerberos Service Ticket Operations

Success

Other Account Logon Events

No Auditing

Kerberos Authentication Service

Success

Credential Validation

Success

Audit Account Management

Computer Account Management

Success

Security Group Management

Success

Distribution Group Management

No Auditing

Application Group Management

No Auditing

Other Account Management Events

No Auditing

User Account Management

Success

Audit Process Tracking

Process Termination

No Auditing

DPAPI Activity

No Auditing

RPC Events

No Auditing

Process Creation

No Auditing

Audit Directory Service Access

Directory Service Changes

No Auditing

Directory Service Replication

No Auditing

Detailed Directory Service Replication

No Auditing

Directory Service Access

Success

Audit Logon Events

Logoff

Success

Account Lockout

Success

IPsec Main Mode

No Auditing

IPsec Quick Mode

No Auditing

IPsec Extended Mode

No Auditing

Special Logon

Success

Other Logon/Logoff Events

No Auditing

Logon

Success and Failure

Audit Object Access

File System

No Auditing

Registry

No Auditing

Kernel Object

No Auditing

SAM

No Auditing

Certification Services

No Auditing

Application Generated

No Auditing

Handle Manipulation

No Auditing

File Share

No Auditing

Filtering Platform Packet Drop

No Auditing

Filtering Platform Connection

No Auditing

Other Object Access Events

No Auditing

Audit Policy Change

Authentication Policy Change

Success

Authorization Policy Change

No Auditing

MPSSVC Rule-Level Policy Change

No Auditing

Filtering Platform Policy Change

No Auditing

Other Policy Change Events

No Auditing

Audit Policy Change

Success

Audit Privilege Use

Non Sensitive Privilege Use

No Auditing

Other Privilege Use Events

No Auditing

Sensitive Privilege Use

No Auditing

Audit System Events

Security System Extension

No Auditing

System Integrity

Success and Failure

IPsec Driver

No Auditing

Other System Events

Success and Failure

Security State Change

Success



Source: http://www.enterpriseitplanet.com/networking/features/article.php/3797931
Email ThisBlogThis!Share to XShare to FacebookShare to Pinterest
Posted in windows 2000 server, windows server 2003, windows server 2008 | No comments
Newer Post Older Post Home

0 comments:

Post a Comment

Subscribe to: Post Comments (Atom)

Popular Posts

  • Windows Server 2008: Active Directory Domain Services Auditing Capabilities Explained
    Active Directory Domain Services Auditing has remained fairly consistent since the first release of Active Directory in Windows 2000 Server...
  • How to Implement Outlook Web Access for Exchange Server 2007
    Implementing Outlook Web Access Once the Client Access role is installed on your Exchange Server , the OWA is available to your remote users...
  • Latest Gmail Outage Raises Concerns for Small Business
    Sometimes, your greatest assets can become costly liabilities. Google's remarkable success and rapid growth over the past few years may ...
  • Four Windows Server 2008 Storage Improvements
    With the release of Windows Server 2008 , Microsoft is making a number of improvements to the server's underlying storage mechanisms. He...
  • Data Recovery Options in Windows 2000 Server
    If your Windows 2000 Server crashes, you may not have to take the long way back to data recovery. Jim Boyce explores several options that m...
  • How to install the Windows 2000 Support Tools to a Windows 2000 Server-based computer
    Support personnel and network administrators can use the Windows 2000 Support Tools to help manage their networks and troubleshoot problems...
  • How do I install or remove Windows on Windows 64 (WoW64) on my Windows Server 2008 R2 server core installation?
    The WoW64 component is named ServerCore-WOW64. To install it, use the standard ocsetup method: Start /w ocsetup ServerCore-WOW64 To uninstal...

Categories

  • Active directory
  • Azaleos SharePoint Services
  • business tech support
  • Dell
  • dell server
  • DHCP server
  • exchange server
  • exchange server 2007
  • file server
  • IBM
  • Internet Information Server
  • IT support services
  • Microosft windows server
  • Microosft windows server 2000
  • Microosft windows server 2003
  • Microsoft Exchange
  • Microsoft Exchange environments
  • Microsoft Home Server
  • Microsoft SQL Server
  • Microsoft Windows
  • Microsoft Windows 2003
  • Microsoft windows server
  • Microsoft Windows Server 2003
  • Policy Patrol 5
  • private network
  • Read-Only Domain Controller
  • Red Hat Linux
  • remote server
  • RFID-Ready Server
  • SBS 2008
  • Security Configuration Wizard
  • server performance
  • server services
  • server support
  • server...
  • Servers
  • SharePoint Services
  • Shutdown Event Tracker
  • slave server
  • small business
  • small business computer support
  • small business server
  • small business server 2003
  • small business server 2008
  • small business VOIP
  • Snow Leopard Server
  • Terminal server
  • Types of Servers
  • virtual server support
  • windows 2000 server
  • Windows 2000 Support Tools
  • windows 2003 server
  • Windows Embedded Server
  • windows home server
  • windows server
  • windows server 2003
  • Windows Server 2003 R2
  • Windows Server 2003 Tips
  • windows server 2008
  • windows server 2008 installation
  • Windows Server 2008 R2
  • Windows Server 2008 R2 Beta
  • windows server 2008 setup
  • Windows Server 2008 Terminal Services
  • Windows server 2008.
  • windows server group
  • Windows Server OS
  • windows server support
  • windows server support services
  • windows small business server
  • windows small business server 2008

Blog Archive

  • ▼  2009 (28)
    • ►  June (5)
    • ►  May (5)
    • ►  April (6)
    • ►  March (4)
    • ▼  February (3)
      • How to Choose IT Network Server Support Company?
      • Windows Server 2008: Active Directory Domain Servi...
      • SBS 2008 to SBS 2008 Migration Fails When "Windows...
    • ►  January (5)
  • ►  2008 (17)
    • ►  December (4)
    • ►  November (4)
    • ►  October (4)
    • ►  September (1)
    • ►  July (3)
    • ►  June (1)
Powered by Blogger.

About Me

Unknown
View my complete profile