Does anyone know of a way to track when a change is made to an access-list on a network share or a specific folder?
I have looked at auditing, but I can't seem to find the correct settings.
Smeglor,
I appreciate the help. I have enabled auditing on the folder and set auditing for Domain Users = Change permissions. I can get the eventvwr to show the event below on a file ACL change. The problem is that it doesn't say which user was granted or removed from the ACL. The change was made by the user Administrator, but the change happened to user test3.
I am getting closer.....
I have enabled auditing on a folder for "change permissions". I then created a new rule group in MOM and a new alert that looks for security event id 560. This will tell me when an ACL has changed. It lets me know the file and who made the ACL change. The one major part I can get it to do is to report back to me which user/group now has access or was removed from an ACL. Below the user that made the change was "Administrator" but the user that was given access was "adtest\test3" to the file c:\acl\test3.txt. Anyone know how to get the event to show this?
This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
By continuing to use this site, you are consenting to our use of cookies.