hidden hit counter
Help!

Audit object access - failure audit

 
  

Post new topic   General Reply to Topic (not reply to a specific post)    Forums Home -> Advanced Server RSS
Next:  Trust Problem??  
Author Message
wbe1981
External


Since: Nov 15, 2006
Posts: 1



PostPosted: Wed Nov 15, 2006 11:37 am    Post subject: Audit object access - failure audit
Archived from groups: microsoft>public>win2000>advanced_server (more info?)

I am having a problem with Failure Audits on W2k3 R2. I have recently
enabled failure auditing for object access. We want to monitor any
attempts by users to access files they shouldn't be accessing. To that
end, I enabled audit object access in Group Policy. It does indeed log
failure audits for objects that are trying to be accessed by otherwise
unauthorized individuals, however, it is also generating what seems to
be "false failures." It is generating Event ID 560 failure audit
entries for EVERYTHING. I tested it and accessed a file that I have
full control over. I checked the security log and it generated the
following failure audit entry;

Event Type: Failure Audit
Event Source: Security
Event Category: Object Access
Event ID: 560
Date: 11/15/2006
Time: 12:35:14 PM
User: DOMAIN\user
Computer: CRA002
Description:
Object Open:
Object Server: Security
Object Type: File
Object Name: D:\Home_Folders\userfolder\Time record.xls
Handle ID: -
Operation ID: {0,2144879367}
Process ID: 4
Image File Name:
Primary User Name: CRA002$
Primary Domain: DOMAIN
Primary Logon ID: (0x0,0x3E7)
Client User Name: wbevertsen
Client Domain: DOMAIN
Client Logon ID: (0x0,0x7FAEEE25)
Accesses: DELETE
READ_CONTROL
ACCESS_SYS_SEC
ReadData (or ListDirectory)
ReadEA
ReadAttributes

Privileges: -
Restricted Sid Count: 0
Access Mask: 0x1030089


For more information, see Help and Support Center at
http://go.microsoft.com/fwlink/events.asp.


Any ideas on how I can stop these "false failures" while retaining the
ability to view GENUINE failures? Thanks!


William E.
MCP
Back to top
Seajman



Joined: Apr 08, 2008
Posts: 1



PostPosted: Tue Apr 08, 2008 10:29 am    Post subject:

This would appear to be a Hotfix issue with Microsoft. I am currently having a Laptop with the same issue filling a security event log every day.

Posting for those who may run into the same issue even though this problem was posted some time ago.

http://support.microsoft.com/kb/908473/en-us
Back to top
Display posts from previous:   
Post new topic   General Reply to Topic (not reply to a specific post)    Forums Home -> Advanced Server All times are: Eastern Time (US & Canada) (change)
Page 1 of 1

 
You can post new topics in this forum
You can reply to topics in this forum
You can edit your posts in this forum
You can delete your posts in this forum
You can vote in polls in this forum