Logo
CAR REVIEW
Windows Vista
Windows 7
Windows Azure
Windows Server
Windows Phone
PREGNANCY
 
 
Windows Server

Windows Server 2008 R2 : Auditing the Environment (part 2) - Audit Policy Subcategories

3/13/2011 3:59:57 PM

Audit Policy Subcategories

Windows Server 2008 R2 allows more granularity in the setting of the audit policies. In previous versions of the Windows Server platform, the audit policies could only be set on the general categories. This usually resulted in a large number of security events, many of which are not of interest to the administrator. System management software was usually needed to help parse all the security events to find and report on the relevant entries. Windows Server 2008 R2 exposes additional subcategories under each of the general categories, which can each be set to No Auditing, Success, Failure, or Success and Failure. These subcategories allow administrators to fine-tune the audited events.

Unfortunately, the audit categories do not quite match the audit policies. Table 3 shows how the categories match the policies.

Table 3. Matching Audit Policies to Audit Categories
Audit PolicyAudit Category
Audit account logon eventsAccount Logon
Audit account managementAccount Management
Audit directory service accessDS Access
Audit logon eventsLogon/Logoff
Audit object accessObject Access
Audit policy changePolicy Change
Audit privilege usePrivilege Use
Audit process trackingDetailed Tracking
Audit system eventsSystem

There are over 50 different subcategories that can be individually set. These give the administrator and security professionals unprecedented control over the events that will generate security log entries. Table 4 lists the categories and the subcategories of audit policies.

Table 4. Audit Subcategories
Audit CategoryAudit Subcategory
SystemSecurity State Change
 Security System Extension
 System Integrity
 IPSec Driver
 Other System Events
Logon/LogoffLogon
 Logoff
 Account Lockout
 IPSec Main Mode
 IPSec Quick Mode
 IPSec Extended Mode
 Special Logon
 Network Policy Server
 Other Logon/Logoff Events
Object AccessFile System
 Registry
 Kernel Object
 SAM
 Certification Services
 Application Generated
 Handle Manipulation
 File Share
 Filtering Platform Packet Drop
 Detailed File Share Filtering Platform Connection
 Other Object Access Events
Privilege UseSensitive Privilege Use
 Non-Sensitive Privilege Use
 Other Privilege Use Events
Detailed TrackingProcess Creation
 Process Termination
 DPAPI Activity
 RPC Events
Policy ChangeAudit Policy Change
 Authentication Policy Change
 Authorization Policy Change
 MPSSVC Rule-Level Policy Change
 Filtering Platform Policy Change
 Other Policy Change Events
Account ManagementUser Account Management
 Computer Account Management
 Security Group Management
 Distribution Group Management
 Application Group Management
 Other Account Management Event
DS AccessDirectory Service Access
 Directory Service Changes
 Directory Service Replication
 Detailed Directory Service Replication
Account LogonKerberos Service Ticket Operations
 Credential Validation
 Kerberos Authentication Service
 Other Account Logon Events

You can use the AUDITPOL command to get and set the audit categories and subcategories. To retrieve a list of all the settings for the audit categories and subcategories, use the following command:

auditpol /get /category:*

To enable auditing of the Distribution Group Management subcategory of the Account Management category for both success and failure events, the following command can be used:

auditpol /set /subcategory:"Distribution Group Management"
/success:enable /failure:enable

This command would need to be run on each domain controller for the policy to have a uniform effect. To get all the options for the Audit Policy command, use the following command:

Other -----------------
- Windows Server 2003 : Configuring Zone Properties and Transfers - Exploring DNS Zone Properties (part 4)
- Windows Server 2003 : Configuring Zone Properties and Transfers - Exploring DNS Zone Properties (part 3)
- Windows Server 2003 : Configuring Zone Properties and Transfers - Exploring DNS Zone Properties (part 2)
- Windows Server 2003 : Configuring Zone Properties and Transfers - Exploring DNS Zone Properties (part 1)
- Windows Server 2008 R2 : Server Manager Storage Page
- Windows Server 2008 R2 : Server Manager Configuration Page
- Windows Server 2008 R2 : Server Manager Diagnostics Page
- Windows Server 2008 R2 : Server Manager
- Managing Windows Server 2008 R2 Roles and Features
- Windows Server 2008 R2 : Initial Configuration Tasks
- Going Green with Windows Server 2008 R2
- Windows Server 2003 : Configuring DNS Server Properties - Exploring DNS Server Properties Tabs
- Windows Server 2003 : Troubleshooting TCP/IP Connections (part 2)
- Windows Server 2003 : Troubleshooting TCP/IP Connections (part 1) - Faulty TCP/IP Configuration & Network Diagnostics
- Windows Server 2008 R2 :Task Scheduler
- Using the Debugging Tools Available in Windows Server 2008 R2 (part 3)
- Using the Debugging Tools Available in Windows Server 2008 R2 (part 2) - TCP/IP Tools
- Using the Debugging Tools Available in Windows Server 2008 R2 (part 1) - Best Practices Analyzer Tools
- Windows Server 2008 R2 : Logging and Debugging - Setting Baseline Values
- Windows Server 2003 : Analyzing Traffic Using Network Monitor (part 3) - Adding Parsers to Network Monitor
 
 
Most view of day
- Extending Dynamics AX 2009 (part 3) - Creating Labels, Adding Content to the Wizard
- Microsoft Lync Server 2010 : Planning for Voice Deployment - Voice Resilience
- Microsoft Lync Server 2013 : Administration of the Director Role (part 2) - Ports,Firewall Rules
- Customizing Windows 7 : Set the Screen Saver
- Microsoft Exchange Server 2010 : Setting Up Transport Rules (part 5) - Creating New Rules with the Exchange Management Shell
- Working with E-mail, Contacts, and Events : Add a File Attachment
- Microsoft Word 2010 : Creating Desktop Publishing Documents - Arranging Text in Columns
- Sharepoint 2013 : SharePoint Designer 2013 (part 1) - New Features
- Designing and Configuring Unified Messaging in Exchange Server 2007 : Monitoring and Troubleshooting Unified Messaging (part 2) - Performance Monitors
- Windows Server 2008 Server Core : Outputting Data Files with the Type Command
Top 10
- Microsoft Project 2010 : Linking Tasks (part 8) - Auditing Task Links,Using the Task Inspector
- Microsoft Project 2010 : Linking Tasks (part 7) - Creating Links by Using the Mouse,Working with Automatic Linking Options
- Microsoft Project 2010 : Linking Tasks (part 6) - Creating Links by Using the Entry Table
- Microsoft Project 2010 : Linking Tasks (part 5) - Creating Links by Using the Task Information Dialog Box
- Microsoft Project 2010 : Linking Tasks (part 4) - Entering Leads and Lags, Creating Links by Using the Menu or Toolbar
- Microsoft Project 2010 : Linking Tasks (part 3) - Using the Start-to-Start Relationship,Using the Finish-to-Finish Relationship
- Microsoft Project 2010 : Linking Tasks (part 2) - Using the Start-to-Start Relationship,Using the Finish-to-Finish Relationship
- Microsoft Project 2010 : Linking Tasks (part 1) - Defining Dependency Links
- Microsoft Project 2010 : Defining Task Logic - Manipulating Your Schedule
- Microsoft Lync Server 2013 : Director Troubleshooting (part 3) - Synthetic Transactions,Telnet
 
 
Windows XP
Windows Vista
Windows 7
Windows Azure
Windows Server
Windows Phone
2015 Camaro