I am getting closer.....
I have enabled auditing on a folder for "change permissions". I then created a new rule group in MOM and a new alert that looks for security event id 560. This will tell me when an ACL has changed. It lets me know the file and who made the ACL change. The one major part I can get it to do is to report back to me which user/group now has access or was removed from an ACL. Below the user that made the change was "Administrator" but the user that was given access was "adtest\test3" to the file c:\acl\test3.txt. Anyone know how to get the event to show this?
This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
By continuing to use this site, you are consenting to our use of cookies.