My firm of app. 40 systems/users switched from Novell to MS 2003 server and I need some recommendations. (1 server, running Active Directory, DNS, DHCP and providing file and print services.)
I have been going through the literature but it is hard to weed through the volume of info. available and I need some immediate guidance.
Yesterday the firm terminated a new hire, something that is very rare for us. I was given a small amount of notice but they notified the person ahead of schedule and I wasn't quite ready. I found that data was being deleted from the network (stroke of luck) and immediately disconnected this person's session and disabled the account. I recovered the data (another stroke of luck, issue for another thread) and we have backup from the previous night so it wouldn't have been devastating had I been unsuccessful.
My questions:
1: How should I prepare for termination of a user?
2: Is there a way to prevent or be alerted to a user deleting large amounts of data?
3: Is there auditing that could be set to track this action? As things stand I cannot prove that this account was used to delete these files (I was able to do this on Netware).
4: I need basic, practical guidelines/advice for setting up domain auditing and security. The docs and knowledgebase articles that I find don't cut to the chase.
Thanks.
Zvi
I have been going through the literature but it is hard to weed through the volume of info. available and I need some immediate guidance.
Yesterday the firm terminated a new hire, something that is very rare for us. I was given a small amount of notice but they notified the person ahead of schedule and I wasn't quite ready. I found that data was being deleted from the network (stroke of luck) and immediately disconnected this person's session and disabled the account. I recovered the data (another stroke of luck, issue for another thread) and we have backup from the previous night so it wouldn't have been devastating had I been unsuccessful.
My questions:
1: How should I prepare for termination of a user?
2: Is there a way to prevent or be alerted to a user deleting large amounts of data?
3: Is there auditing that could be set to track this action? As things stand I cannot prove that this account was used to delete these files (I was able to do this on Netware).
4: I need basic, practical guidelines/advice for setting up domain auditing and security. The docs and knowledgebase articles that I find don't cut to the chase.
Thanks.
Zvi