Server Admin I Unit 8.4 Audit Policy Flashcards
auditing
Recording of system events and other system changes which are enabled by audit policies
Account Logon Audit Policy(2)
Tracks when a user account authenticates to a computer.
Local user accounts are recorded on local computer and domain user accounts are recorded on domain controller
Event Log Subscription
Allows for centralizing of event logs from multiple computers.
Account Management Audit Policy
Tracks changes to user accounts including create, rename, disable/enable, delete, and password changes.
Directory Service Access
Tracks changes to Active Directory objects.
4 Subcategories of Directory Service
- Directory Service Access
- Directory Service Changes
- Directory Service Replication
- Detailed Directory Service Replication
What is the difference between Directory Service Access Audit Policy and Directory Service Changes Audit Policy?
Directory Service Access tells when a change was made.
Directory Service Changes records the values for the original setting as well as the values for the change.
auditpol/set/
cmd to enable auditing for individual categories
Logon Audit Policy
Tracks login/off on local system or when network connection is made.
Object Access Audit Policy
Tracks access to files , folders, printers, certificate authority actions, access to specific registry settings, or access to specific Internet Information Services Metabase settings.
Policy Change Audit Policy
Tracks changes to user rights, trust relationships, IPsec and Kerberos policies or audit policies.
Priviledge Use Audit Policy
Tracks when a user exercises a user right or when admin takes ownership of an object.
Process Tracking Audit Policy
Records actions taken by applications, which is mainly used for debugging and tracking.
System Audit Policy
Tracks system shutdown, restart, or system services starts.
Where must auditing be enabled for Directory Service Access & Object Access Audit Policies ?
- Enable auditing in local security policy or Group Policy.
2. Configure auditing in specific objects to be tracked.
System Access Control List of AD object or NTFS file/folder