On a users folder I have auditing set to log failed list folder read data object access attemps so I can see who is attempting to access this folder. This seems to be working but for some reason certain files within the folder are being flagged when the actual user accesses them even though she has full control of the files and opens them no problem. Event as below, why would this be?
Accesses: DELETE
READ_CONTROL
ACCESS_SYS_SEC
ReadData (or ListDirectory)
ReadEA
ReadAttributes
Privileges: -
Restricted Sid Count: 0
Access Mask: 0x1030089
Accesses: DELETE
READ_CONTROL
ACCESS_SYS_SEC
ReadData (or ListDirectory)
ReadEA
ReadAttributes
Privileges: -
Restricted Sid Count: 0
Access Mask: 0x1030089