Back learn.microsoft.com Planning and deploying advanced security audit policies
Access to this page requires authorization. You can try signing in or changing directories .
Access to this page requires authorization. You can try changing directories .
Applies To: Windows HPC Server 2008 R2, Windows 7, Windows 8.1, Windows Server 2012 R2, Windows Server 2012, Windows 8
This topic for the IT professional explains the options that security policy planners must consider and the tasks they must complete to deploy an effective security audit policy in a network that includes Advanced Security Audit policies.
Organizations invest a large portion of their information technology budgets on security applications and services, such as antivirus software, firewalls, and encryption. But no matter how much security hardware or software you deploy, how tightly you control the rights of users, or how carefully you configure security permissions on your data, you should not consider the job complete unless you have a well-defined, timely auditing strategy to track the effectiveness of your defenses and identify attempts to circumvent them.
To be well defined and timely, an auditing strategy must provide useful tracking data for an organization's most important resources, critical behaviors, and potential risks. In a growing number of organizations, it must also provide absolute proof that IT operations comply with corporate and regulatory requirements.
Unfortunately, no organization has unlimited resources to monitor every resource and activity on a network. If you do not plan well, you will likely have gaps in your auditing strategy. However, if you try to audit every resource and activity, you may find yourself with far too much monitoring data, including thousands of benign audit entries that an analyst needs to sift through to identify the narrow set of entries that warrant closer examination. This could cause delays or even prevent auditors from identifying suspicious activity. Thus, too much monitoring can leave an organization as vulnerable as not enough monitoring.
Auditing features introduced in Windows 7 and Windows Server 2008 R2 made it easier to audit important user, computer, and network activities in a focused, efficient manner. These features include:
Advanced audit policy settings Allow administrators to more narrowly apply and manage detailed audit policy settings through their existing Group Policy framework.
Advanced audit policy settings Allow administrators to more narrowly apply and manage detailed audit policy settings through their existing Group Policy framework.
"Reason for access" auditing Enables administrators to specify and identify the permissions that were used to generate a particular object access security event.
"Reason for access" auditing Enables administrators to specify and identify the permissions that were used to generate a particular object access security event.
Global object access auditing Allows administrators to define system access control lists (SACLs) for an entire computer file system or registry.
Global object access auditing Allows administrators to define system access control lists (SACLs) for an entire computer file system or registry.
To deploy these features and plan an effective security auditing strategy, you need to:
Identify your most critical resources and the most important activities that need to be tracked.
Identify your most critical resources and the most important activities that need to be tracked.
Identify the audit settings that can be used to track these activities.
Identify the audit settings that can be used to track these activities.
Assess the advantages and potential costs associated with each.
Assess the advantages and potential costs associated with each.
Test these settings to validate your choices.
Test these settings to validate your choices.
Develop plans for deploying and managing your audit policy.
Develop plans for deploying and managing your audit policy.
This document will guide you through the steps needed to plan a security auditing policy that uses Windows auditing features. This policy must identify and address vital business needs, including:
Regulatory requirements
Regulatory requirements
Protection of the organization's data and intellectual property
Protection of the organization's data and intellectual property
Users, including employees, contractors, partners, and customers
Users, including employees, contractors, partners, and customers
Client computers and applications
Client computers and applications
Servers and the applications and services running on those servers
Servers and the applications and services running on those servers
The audit policy also must identify processes for managing audit data after it has been logged, including:
Collecting, evaluating, and reviewing audit data
Collecting, evaluating, and reviewing audit data
Storing and (if required) disposing of audit data
Storing and (if required) disposing of audit data
Supported versions of Windows
Basic security audit policy settings
The basic security audit policy settings can be used to log audit events on any computer running any of the supported versions of Windows in addition to Windows Server 2008, Windows Server 2003, Windows 2000 Server, or a computer running Windows Vista, Windows XP, or Windows 2000 that can join a domain.
Supported versions are designated in the Applies To list at the beginning of this topic,
Advanced audit policy settings
The advanced audit policy settings can be configured and used to log audit events on any computer running any of the supported versions of Windows.
In addition, the advanced audit policy settings can be applied by using a logon script on computers running Windows Vista or Windows Server 2008.
Terminology used in this guide
Understanding the following terms will help you apply the guidance in this document:
Group Policy. The Windows feature that allows administrators to specify options to manage configurations for groups of computers and users.
Group Policy. The Windows feature that allows administrators to specify options to manage configurations for groups of computers and users.
Audit policy. The nine security audit policy settings under Security Settings\Local Policies\Audit Policy and 53 audit policy settings under Security Settings\Advanced Audit Policy Configuration that determine the security events to be recorded in the security event log.
Audit policy. The nine security audit policy settings under Security Settings\Local Policies\Audit Policy and 53 audit policy settings under Security Settings\Advanced Audit Policy Configuration that determine the security events to be recorded in the security event log.
Success audit. An audit event that is triggered when a defined action, such as accessing a file , is completed successfully.
Success audit. An audit event that is triggered when a defined action, such as accessing a file , is completed successfully.
Failure audit. An audit event that is triggered when a defined action, such as a user logon, is not completed successfully.
Failure audit. An audit event that is triggered when a defined action, such as a user logon, is not completed successfully.
System access control lists (SACLs). A section of the security descriptor for objects, which is used to maintain per-object auditing information. For many types of objects, such as file system objects or registry settings, audit events are logged only if the relevant audit policy has been applied to the computer and a corresponding SACL has been configured on the object. However, you can ensure that a system-wide SACL is applied to all file system objects or all registry settings on a computer by using global object access auditing.
System access control lists (SACLs). A section of the security descriptor for objects, which is used to maintain per-object auditing information. For many types of objects, such as file system objects or registry settings, audit events are logged only if the relevant audit policy has been applied to the computer and a corresponding SACL has been configured on the object. However, you can ensure that a system-wide SACL is applied to all file system objects or all registry settings on a computer by using global object access auditing.
"Reason for access" audit. This list of access control entries (ACEs) provides the rights for which the decision to allow or deny access to the object was based. This can be useful for documenting the permissions, such as group memberships, that allow or prevent the occurrence of a particular auditable event. For more information using "reason for access" auditing, see the Advanced Security Auditing Walkthrough .
"Reason for access" audit. This list of access control entries (ACEs) provides the rights for which the decision to allow or deny access to the object was based. This can be useful for documenting the permissions, such as group memberships, that allow or prevent the occurrence of a particular auditable event. For more information using "reason for access" auditing, see the Advanced Security Auditing Walkthrough .
Global object access auditing. In any of the supported versions of Windows , a computer-wide SACL can be applied to all objects in the file system or to all registry settings. The specified SACL is automatically applied to every object of that type, overriding any other SACLS that are configured for or applied to that object. For more information using global object access auditing, see the Advanced Security Auditing Walkthrough .
Global object access auditing. In any of the supported versions of Windows , a computer-wide SACL can be applied to all objects in the file system or to all registry settings. The specified SACL is automatically applied to every object of that type, overriding any other SACLS that are configured for or applied to that object. For more information using global object access auditing, see the Advanced Security Auditing Walkthrough .
Understanding the security audit policy design process
The process of designing and deploying a Windows security audit policy involves the following tasks, which are described in greater detail throughout this document:
Identifying your Windows security audit policy deployment goals This section helps define the business objectives that will guide your Windows security audit policy. It also helps you define the resources, users, and computers that will be the focus of your security auditing.
Identifying your Windows security audit policy deployment goals
This section helps define the business objectives that will guide your Windows security audit policy. It also helps you define the resources, users, and computers that will be the focus of your security auditing.
Mapping the security audit policy to groups of users, computers, and resources in your organization This section explains how to integrate security audit policy settings with domain Group Policy settings for different groups of users, computers, and resources. In addition, if your network includes multiple versions of Windows client and server operating systems, it also explains when to use basic audit policy settings and when to use advanced security audit policy settings.
Mapping the security audit policy to groups of users, computers, and resources in your organization
This section explains how to integrate security audit policy settings with domain Group Policy settings for different groups of users, computers, and resources. In addition, if your network includes multiple versions of Windows client and server operating systems, it also explains when to use basic audit policy settings and when to use advanced security audit policy settings.
Mapping your security auditing goals to a security audit policy configuration This section explains the categories of Windows security auditing settings that are available. It also identifies individual Windows security auditing policy settings that can be of particular value to address auditing scenarios.
Mapping your security auditing goals to a security audit policy configuration
This section explains the categories of Windows security auditing settings that are available. It also identifies individual Windows security auditing policy settings that can be of particular value to address auditing scenarios.
Planning for security audit monitoring and management This section helps you plan to collect, analyze, and store Windows audit data. Depending on the number of computers and types of activity that you want to audit, Windows event logs can fill up quickly. In addition, this section explains how auditors can access and aggregate event data from multiple servers and desktop computers. It also explains how to address storage requirements, including how much audit data to store and how it must be stored.
Planning for security audit monitoring and management
This section helps you plan to collect, analyze, and store Windows audit data. Depending on the number of computers and types of activity that you want to audit, Windows event logs can fill up quickly. In addition, this section explains how auditors can access and aggregate event data from multiple servers and desktop computers. It also explains how to address storage requirements, including how much audit data to store and how it must be stored.
Deploying the security audit policy This section provides recommendations and guidelines for the effective deployment of a Windows security audit policy. Configuring and deploying Windows audit policy settings in a test lab environment can help you confirm that the settings you have selected will produce the type of audit data you need. However, only a carefully staged pilot and incremental deployments based on your domain and organizational unit (OU) structure will enable you to confirm that the audit data you generate can be monitored and that it meets your organization's audit needs.
Deploying the security audit policy
This section provides recommendations and guidelines for the effective deployment of a Windows security audit policy. Configuring and deploying Windows audit policy settings in a test lab environment can help you confirm that the settings you have selected will produce the type of audit data you need. However, only a carefully staged pilot and incremental deployments based on your domain and organizational unit (OU) structure will enable you to confirm that the audit data you generate can be monitored and that it meets your organization's audit needs.
Identifying your Windows security audit policy deployment goals
A security audit policy must support and be a critical and integrated aspect of an organization's overall security design and framework.
Every organization has a unique set of data and network assets (such as customer and financial data and trade secrets), physical resources (such as desktop computers, portable computers, and servers), and users (which can include various internal groups such as finance and marketing, and external groups such as partners, customers, and anonymous users on the website). Not all of these assets, resources, and users justify the cost of an audit. Your task is to identify which assets, resources, and users provide the strongest justification for the focus of a security audit.
To create your Windows security audit plan, begin by identifying:
The overall network environment, including the domains, OUs, and security groups.
The overall network environment, including the domains, OUs, and security groups.
The resources on the network, the users of those resources, and how those resources are being used.
The resources on the network, the users of those resources, and how those resources are being used.
Regulatory requirements.
Regulatory requirements.
An organization's domain and OU structure provide a fundamental starting point for thinking how to apply a security audit policy because it likely provides a foundation of Group Policy Objects (GPOs) and logical grouping of resources and activities that you can use to apply the audit settings that you choose. It is also likely that certain portions of your domain and OU structure already provide logical groups of users, resources, and activities that justify the time and resources needed to audit them. For information how to integrate a security audit policy with your domain and OU structure, see Mapping the security audit policy to groups of users, computers, and resources in your organization later in this document.
In addition to your domain model, you should also find out whether your organization creates and maintains a systematic threat model. A good threat model can help you identify threats to key components in your infrastructure, so you can define and apply audit settings that enhance the organization's ability to identify and counter those threats.
Including auditing within your organization's security plan also makes it possible to budget your resources on the areas where auditing can achieve the most positive results.
For additional details how to complete each of these steps and how to prepare a detailed threat model, download the IT Infrastructure Threat Modeling Guide .
For data and resource auditing, you need to identify the most important types of data and resources (such as patient records, accounting data, or marketing plans) that can benefit from the closer monitoring that Windows auditing can provide. Some of these data resources might already be monitored through auditing features in products such as Microsoft SQL Server and Exchange Server. If so, you may want to consider how Windows auditing features can enhance the existing audit strategy. As with the domain and OU structure discussed previously, security auditing should focus on your most critical resources. You also must consider how much audit data you will be able to manage.
You can record if these resources have high business impact, medium business impact, or low business impact, the cost to the organization if these data resources are accessed by unauthorized users, and the risk that this access can pose to the organization. The type of access by users (such as Read, Modify, or Copy) can also pose different levels of risk to an organization.
Increasingly, data access and use is governed by regulations, and a breach can result in severe penalties and a loss in credibility for the organization. If regulatory compliance plays a role in how you manage your data, be sure to also document this information.
The following table provides an example of a resource analysis for an organization.
Security or regulatory requirements
Accounting: Read/Write on Corp-Finance-1
Departmental Payroll Managers: Write only on Corp-Finance-1
Financial integrity and employee privacy
Patient medical records
Doctors and Nurses: Read/Write on Med/Rec-2
Lab Assistants: Write only on MedRec-2
Accounting: Read only on MedRec-2
Strict legal and regulatory standards
Consumer health information
Public Relations Web Content Creators: Read/Write on Web-Ext-1
Public: Read only on Web-Ext-1
Public education and corporate image
Many organizations find it useful to classify the types of users they have and base permissions on this classification. This same classification can help you identify which user activities should be the subject of security auditing and the amount of audit data they will generate.
Organizations can create distinctions based on the type of rights and permissions needed by users to perform their jobs. For example, under the classification Administrators, larger organizations might assign local administrator responsibilities for a single computer, for specific applications such as Exchange Server or SQL Server, or for an entire domain. Under Users, permissions and Group Policy settings can apply to as many as all users in an organization or as few as a subset of the employees in a given department.
Also, if your organization is subject to regulatory requirements, user activities such as accessing medical records or financial data may need to be audited to verify that you are complying with these requirements.
To effectively audit user activity, begin by listing the different types of users in your organization and the types of data they need access to—in addition to the data they should not have access to.
Also, if external users can access any of your organization's data, be sure to identify them, including if they belong to a business partner, customer, or general user, the data they have access to, and the permissions they have to access that data.
The following table illustrates an analysis of users on a network. Although our example contains a single column titled "Possible auditing considerations," you may want to create additional columns to differentiate between different types of network activity, such as logon hours and permission use.
Possible auditing considerations
Account administrators
User accounts and security groups
Account administrators have full privileges to create new user accounts, reset passwords, and modify security group memberships. We need a mechanism to monitor these changes.
Members of the Finance OU
Users in Finance have Read/Write access to critical financial records, but no ability to change permissions on these resources. These financial records are subject to government regulatory compliance requirements.
Employees of partner organizations have Read/Write access to certain project data and servers relating to Project Z, but not to other servers or data on the network.
Security and auditing requirements and audit event volume can vary considerably for different types of computers in an organization. These requirements can be based on:
If the computers are servers, desktop computers, or portable computers.
If the computers are servers, desktop computers, or portable computers.
The important applications the computers run, such as Exchange Server, SQL Server, or Forefront Identity Manager. Note If the server applications (including Exchange Server and SQL Server) have audit settings. For more information auditing in Exchange Server, see the Exchange 2010 Security Guide . For more information auditing in SQL Server 2008, see Auditing (Database Engine) . For SQL Server 2012, see SQL Server Audit (Database Engine) .
The important applications the computers run, such as Exchange Server, SQL Server, or Forefront Identity Manager.
If the server applications (including Exchange Server and SQL Server) have audit settings. For more information auditing in Exchange Server, see the Exchange 2010 Security Guide . For more information auditing in SQL Server 2008, see Auditing (Database Engine) . For SQL Server 2012, see SQL Server Audit (Database Engine) .
The operating system versions. Note The operating system version determines which auditing options are available and the volume of audit event data.
The operating system versions.
The operating system version determines which auditing options are available and the volume of audit event data.
The business value of the data.
The business value of the data.
For example, a web server that is accessed by external users requires different audit settings than a root certification authority (CA) that is never exposed to the public Internet or even to regular users on the organization's network.
The following table illustrates an analysis of computers in an organization.
Type of computer and applications
Operating system version
Servers hosting Exchange Server
Separate resource OUs by department and (in some cases) by location
Separate portable computer OUs by department and (in some cases) by location
Regulatory requirements
Many industries and locales have strict and specific requirements for network operations and how resources are protected. In the health care and financial industries, for example, there are strict guidelines for who has access to records and how they are used. Many countries have strict privacy rules. To identify regulatory requirements, work with your organization's legal department and other departments responsible for these requirements. Then consider the security configuration and auditing options that can be used to comply with and verify compliance with these regulations.
For more information, see the System Center Process Pack for IT GRC .
Mapping the security audit policy to groups of users, computers, and resources in your organization
The policy settings you identify can be applied by using one or more GPOs. To create and edit a GPO, use the Group Policy Management Console (GPMC). By using the GPMC to link a GPO to selected Active Directory sites, domains, and OUs, you apply the policy settings in the GPO to the users and computers in those Active Directory objects. An OU is the lowest-level Active Directory container to which you can assign Group Policy settings.
The policy settings you identify can be applied by using one or more GPOs. To create and edit a GPO, use the Group Policy Management Console (GPMC). By using the GPMC to link a GPO to selected Active Directory sites, domains, and OUs, you apply the policy settings in the GPO to the users and computers in those Active Directory objects. An OU is the lowest-level Active Directory container to which you can assign Group Policy settings.
For every policy setting that you select, you need to decide whether it should be enforced across the organization, or whether it should apply only to selected users or computers. You can then combine these audit policy settings into GPOs and link them to the appropriate Active Directory containers.
For every policy setting that you select, you need to decide whether it should be enforced across the organization, or whether it should apply only to selected users or computers. You can then combine these audit policy settings into GPOs and link them to the appropriate Active Directory containers.
For example, you might use a domain GPO to assign an organization-wide group of audit settings, but want a certain OU to get a defined group of additional settings. To accomplish this, you can link a second GPO to that specific lower-level OU. Therefore, a logon audit setting that is applied at the OU level will override a conflicting logon audit setting that is applied at the domain level (unless you have taken special steps to apply Group Policy loopback processing).
Audit policies are computer policies. Therefore, they must be applied through GPOs that are applied to computer OUs, not to user OUs. However, in most cases you can apply audit settings for only specified resources and groups of users by configuring SACLs on the relevant objects. This enables auditing for a security group that contains only the users you specify. For example, you could configure a SACL for a folder called Payroll Data on Accounting Server 1. This can audit attempts by members of the Payroll Processors OU to delete objects from this folder. The Object Access\Audit File System audit policy setting applies to Accounting Server 1, but because it requires a corresponding resource SACL, only actions by members of the Payroll Processors OU on the Payroll Data folder generates audit events.
Audit policies are computer policies. Therefore, they must be applied through GPOs that are applied to computer OUs, not to user OUs. However, in most cases you can apply audit settings for only specified resources and groups of users by configuring SACLs on the relevant objects. This enables auditing for a security group that contains only the users you specify.
For example, you could configure a SACL for a folder called Payroll Data on Accounting Server 1. This can audit attempts by members of the Payroll Processors OU to delete objects from this folder. The Object Access\Audit File System audit policy setting applies to Accounting Server 1, but because it requires a corresponding resource SACL, only actions by members of the Payroll Processors OU on the Payroll Data folder generates audit events.
Advanced security audit policy settings were introduced in Windows Server 2008 R2 or Windows 7 and can be applied to those operating systems designated in the Applies To list at the beginning of this topic. These advanced audit polices can only be applied by using Group Policy. Note These settings can also be applied to computers running Windows Vista or Windows Server 2008, but with these operating systems you must use logon scripts to apply advanced audit policies. Therefore, consider upgrading computers in high-security OUs first so that you can use Group Policy to apply and manage advanced audit policies to monitor high-value computers and their users. Important Whether you apply advanced audit policies by using Group Policy or by using logon scripts, do not use both the basic audit policy settings under Local Policies\Audit Policy and the advanced settings under Security Settings\Advanced Audit Policy Configuration . Using both basic and advanced audit policy settings can cause unexpected results in audit reporting. If you use Advanced Audit Policy Configuration settings or use logon scripts (for computers running Windows Vista or Windows Server 2008) to apply advanced audit policies, be sure to enable the Audit: Force audit policy subcategory settings (Windows Vista or later) to override audit policy category settings policy setting under Local Policies\Security Options . This will prevent conflicts between similar settings by forcing basic security auditing to be ignored. For more information, see article 921469 in the Microsoft Knowledge Base.
Advanced security audit policy settings were introduced in Windows Server 2008 R2 or Windows 7 and can be applied to those operating systems designated in the Applies To list at the beginning of this topic. These advanced audit polices can only be applied by using Group Policy.
These settings can also be applied to computers running Windows Vista or Windows Server 2008, but with these operating systems you must use logon scripts to apply advanced audit policies. Therefore, consider upgrading computers in high-security OUs first so that you can use Group Policy to apply and manage advanced audit policies to monitor high-value computers and their users.
Whether you apply advanced audit policies by using Group Policy or by using logon scripts, do not use both the basic audit policy settings under Local Policies\Audit Policy and the advanced settings under Security Settings\Advanced Audit Policy Configuration . Using both basic and advanced audit policy settings can cause unexpected results in audit reporting. If you use Advanced Audit Policy Configuration settings or use logon scripts (for computers running Windows Vista or Windows Server 2008) to apply advanced audit policies, be sure to enable the Audit: Force audit policy subcategory settings (Windows Vista or later) to override audit policy category settings policy setting under Local Policies\Security Options . This will prevent conflicts between similar settings by forcing basic security auditing to be ignored.
For more information, see article 921469 in the Microsoft Knowledge Base.
The following are examples of how audit policies can be applied to an organization's OU structure:
Apply data activity settings to an OU that contains file servers. If your organization has servers that contain particularly sensitive data, consider putting them in a separate OU so that you can configure and apply a more precise audit policy to these servers.
Apply data activity settings to an OU that contains file servers. If your organization has servers that contain particularly sensitive data, consider putting them in a separate OU so that you can configure and apply a more precise audit policy to these servers.
Apply user activity audit policies to an OU that contains all computers in the organization. If your organization places users in OUs based on the department they work in, consider configuring and applying more detailed security permissions on critical resources that are accessed by employees who work in more sensitive areas, such as network administrators or the legal department.
Apply user activity audit policies to an OU that contains all computers in the organization. If your organization places users in OUs based on the department they work in, consider configuring and applying more detailed security permissions on critical resources that are accessed by employees who work in more sensitive areas, such as network administrators or the legal department.
Apply network and system activity audit policies to OUs that contain the organization's most critical servers, such as domain controllers, CAs, email servers, or database servers.
Apply network and system activity audit policies to OUs that contain the organization's most critical servers, such as domain controllers, CAs, email servers, or database servers.
For more information planning and deploying Group Policy, see the Group Policy Planning and Deployment Guide .
Mapping your security auditing goals to a security audit policy configuration
After you identify your security auditing goals, you can begin to map them to a security audit policy configuration. This audit policy configuration must address your most critical security auditing goals, but it also must address your organization's constraints, such as the number of computers that need to be monitored, the number of activities that you want to audit, the number of audit events that your desired audit configuration will generate, and the number of administrators available to analyze and act upon audit data.
To create your audit policy configuration, you need to:
Explore all of the audit policy settings that can be used to address your needs.
Explore all of the audit policy settings that can be used to address your needs.
Choose the audit settings that will most effectively address the audit requirements identified in the section.
Choose the audit settings that will most effectively address the audit requirements identified in the section.
Confirm that the settings you choose are compatible with the operating systems running on the computers that you want to monitor.
Confirm that the settings you choose are compatible with the operating systems running on the computers that you want to monitor.
Decide which configuration options (Success, Failure, or both Success and Failure) you want to use for the audit settings.
Decide which configuration options (Success, Failure, or both Success and Failure) you want to use for the audit settings.
Deploy the audit settings in a lab or test environment to verify that they meet your desired results in terms of volume, supportability, and comprehensiveness. Then deploy the audit settings in a pilot production environment to ensure that your estimates of how much audit data your audit plan will generate are realistic and that you can manage this data.
Deploy the audit settings in a lab or test environment to verify that they meet your desired results in terms of volume, supportability, and comprehensiveness. Then deploy the audit settings in a pilot production environment to ensure that your estimates of how much audit data your audit plan will generate are realistic and that you can manage this data.
Exploring audit policy options
Security audit policy settings in the supported versions of Windows can be viewed and configured in the following locations:
Security Settings\Local Policies\Audit Policy . For more information, see Audit Policy Settings Under Local Policies\Audit Policy .
Security Settings\Local Policies\Audit Policy . For more information, see Audit Policy Settings Under Local Policies\Audit Policy .
Security Settings\Local Policies\Security Options . For more information, see Audit Policy Settings Under Local Policies\Security Options .
Security Settings\Local Policies\Security Options . For more information, see Audit Policy Settings Under Local Policies\Security Options .
Security Settings\Advanced Audit Policy Configuration . For more information, see Advanced Security Audit Policy Settings .
Security Settings\Advanced Audit Policy Configuration . For more information, see Advanced Security Audit Policy Settings .
Choosing audit settings to use
Depending on your goals, different sets of audit settings may be of particular value to you. For example, some settings under Security Settings\Advanced Audit Policy Configuration can be used to monitor the following types of activity:
These are only some of the settings that you should consider. For additional settings and their descriptions, see the Audit Policy Settings Under Local Policies\Security Options . Settings that are described in the Reference might also provide valuable information activity audited by another setting. For example, the settings used to monitor user activity and network activity have obvious relevance to protecting your data resources. Likewise, attempts to compromise data resources have huge implications for overall network status, and potentially for how well you are managing the activities of users on the network.
Data and resource activity
For many organizations, compromising the organization's data resources can cause tremendous financial losses, in addition to lost prestige and legal liability. If your organization has critical data resources that need to be protected against any breach, the following settings can provide extremely valuable monitoring and forensic data:
Object Access\ Audit File . This policy setting allows you to track what content was accessed, the source (IP address and port) of the request, and the user account that was used for the access. The volume of event data generated by this setting will vary depending on the number of client computers that attempt to access the file . On a file server or domain controller, volume may be high due to SYSVOL access by client computers for policy processing. If you do not need to record routine access by client computers that have permissions on the file , you may want to log audit events only for failed attempts to access the file .
Object Access\ Audit File . This policy setting allows you to track what content was accessed, the source (IP address and port) of the request, and the user account that was used for the access. The volume of event data generated by this setting will vary depending on the number of client computers that attempt to access the file . On a file server or domain controller, volume may be high due to SYSVOL access by client computers for policy processing. If you do not need to record routine access by client computers that have permissions on the file , you may want to log audit events only for failed attempts to access the file .
Object Access\ Audit File System . This policy setting determines whether the operating system audits user attempts to access file system objects. Audit events are only generated for objects (such as files and folders) that have configured SACLs, and only if the type of access requested (such as Write, Read, or Modify) and the account that is making the request match the settings in the SACL. If success auditing is enabled, an audit entry is generated each time any account successfully accesses a file system object that has a matching SACL. If failure auditing is enabled, an audit entry is generated each time any user unsuccessfully attempts to access a file system object that has a matching SACL. The amount of audit data generated by the Audit File System policy setting can vary considerably, depending on the number of objects that have been configured to be monitored. Note To audit user attempts to access all file system objects on a computer, use the Global Object Access Auditing settings Registry (Global Object Access Auditing) or File System (Global Object Access Auditing) .
Object Access\ Audit File System . This policy setting determines whether the operating system audits user attempts to access file system objects. Audit events are only generated for objects (such as files and folders) that have configured SACLs, and only if the type of access requested (such as Write, Read, or Modify) and the account that is making the request match the settings in the SACL.
If success auditing is enabled, an audit entry is generated each time any account successfully accesses a file system object that has a matching SACL. If failure auditing is enabled, an audit entry is generated each time any user unsuccessfully attempts to access a file system object that has a matching SACL. The amount of audit data generated by the Audit File System policy setting can vary considerably, depending on the number of objects that have been configured to be monitored.
To audit user attempts to access all file system objects on a computer, use the Global Object Access Auditing settings Registry (Global Object Access Auditing) or File System (Global Object Access Auditing) .
Object Access\ Audit Handle Manipulation . This policy setting determines whether the operating system generates audit events when a handle to an object is opened or closed. Only objects with configured SACLs generate these events, and only if the attempted handle operation matches the SACL. Event volume can be high, depending on how SACLs are configured. When used together with the Audit File System or Audit Registry policy settings, the Audit Handle Manipulation policy setting can provide an administrator with useful "reason for access" audit data that details the precise permissions on which the audit event is based. For example, if a file is configured as a Read-only resource but a user attempts to save changes to the file, the audit event will log not only the event, but also the permissions that were used (or attempted to be used) to save the file changes.
Object Access\ Audit Handle Manipulation . This policy setting determines whether the operating system generates audit events when a handle to an object is opened or closed. Only objects with configured SACLs generate these events, and only if the attempted handle operation matches the SACL.
Event volume can be high, depending on how SACLs are configured. When used together with the Audit File System or Audit Registry policy settings, the Audit Handle Manipulation policy setting can provide an administrator with useful "reason for access" audit data that details the precise permissions on which the audit event is based. For example, if a file is configured as a Read-only resource but a user attempts to save changes to the file, the audit event will log not only the event, but also the permissions that were used (or attempted to be used) to save the file changes.
Global Object Access Auditing . A growing number of organizations are using security auditing to comply with regulatory requirements that govern data security and privacy. But demonstrating that strict controls are being enforced can be extremely difficult. To address this issue, the supported versions of Windows include two Global Object Access Auditing policy settings, one for the registry and one for the file system. When you configure these settings, they apply a global system access control SACL on all objects of that class on a system, which cannot be overridden or circumvented. Important The Global Object Access Auditing policy settings must be configured and applied in conjunction with the Audit File System and Audit Registry audit policy settings in the Object Access category. For more information using the Global Object Access Auditing policy settings, see the Advanced Security Auditing Walkthrough .
Global Object Access Auditing . A growing number of organizations are using security auditing to comply with regulatory requirements that govern data security and privacy. But demonstrating that strict controls are being enforced can be extremely difficult. To address this issue, the supported versions of Windows include two Global Object Access Auditing policy settings, one for the registry and one for the file system. When you configure these settings, they apply a global system access control SACL on all objects of that class on a system, which cannot be overridden or circumvented.
The Global Object Access Auditing policy settings must be configured and applied in conjunction with the Audit File System and Audit Registry audit policy settings in the Object Access category. For more information using the Global Object Access Auditing policy settings, see the Advanced Security Auditing Walkthrough .
The settings in the section relate to activity involving the files, folders, and network shares that are stored on a network, and the settings in this section focus on the users, including employees, partners, and customers, who may try to access those resources.
In the majority of cases, these attempts will be legitimate and a network needs to make vital data readily available to legitimate users. However in other cases, employees, partners, and others may attempt to access resources that they have no legitimate reason to access. Security auditing can be used to track a wide variety of user activities on a particular computer to diagnose and resolve problems for legitimate users and identify and address illegitimate activities. The following are a few important settings that you should evaluate to track user activity on your network:
Account Logon\ Audit Credential Validation . This is an extremely important policy setting because it enables you to track every successful and unsuccessful attempt to present credentials for a user logon. In particular, a pattern of unsuccessful attempts may indicate that a user or application is using credentials that are no longer valid, or attempting to use a variety of credentials in succession in hope that one of these attempts will eventually be successful. These events occur on the computer that is authoritative for the credentials. For domain accounts, the domain controller is authoritative. For local accounts, the local computer is authoritative.
Account Logon\ Audit Credential Validation . This is an extremely important policy setting because it enables you to track every successful and unsuccessful attempt to present credentials for a user logon. In particular, a pattern of unsuccessful attempts may indicate that a user or application is using credentials that are no longer valid, or attempting to use a variety of credentials in succession in hope that one of these attempts will eventually be successful. These events occur on the computer that is authoritative for the credentials. For domain accounts, the domain controller is authoritative. For local accounts, the local computer is authoritative.
Detailed Tracking\ Audit Process Creation and Detailed Tracking\ Audit Process Termination . These policy settings can enable you to monitor the applications that a user opens and closes on a computer.
Detailed Tracking\ Audit Process Creation and Detailed Tracking\ Audit Process Termination . These policy settings can enable you to monitor the applications that a user opens and closes on a computer.
DS Access\ Audit Directory Service Access and DS Access\ Audit Directory Service Changes . These policy settings provide a detailed audit trail of attempts to access create, modify, delete, move, or undelete objects in Active Directory Domain Services (AD DS). Only domain administrators have permissions to modify AD DS objects, so it is extremely important to identify malicious attempts to modify these objects. In addition, although domain administrators should be among an organization's most trusted employees, the use of Audit Directory Service Access and Audit Directory Service Changes settings allow you to monitor and verify that only approved changes are made to AD DS. These audit events are logged only on domain controllers.
DS Access\ Audit Directory Service Access and DS Access\ Audit Directory Service Changes . These policy settings provide a detailed audit trail of attempts to access create, modify, delete, move, or undelete objects in Active Directory Domain Services (AD DS). Only domain administrators have permissions to modify AD DS objects, so it is extremely important to identify malicious attempts to modify these objects. In addition, although domain administrators should be among an organization's most trusted employees, the use of Audit Directory Service Access and Audit Directory Service Changes settings allow you to monitor and verify that only approved changes are made to AD DS. These audit events are logged only on domain controllers.
Logon/Logoff\ Audit Account Lockout . Another common security scenario occurs when a user attempts to log on with an account that has been locked out. It is important to identify these events and to determine whether the attempt to use an account that has been locked out is malicious.
Logon/Logoff\ Audit Account Lockout . Another common security scenario occurs when a user attempts to log on with an account that has been locked out. It is important to identify these events and to determine whether the attempt to use an account that has been locked out is malicious.
Logon/Logoff\ Audit Logoff and Logon/Logoff\ Audit Logon . Logon and logoff events are essential to tracking user activity and detecting potential attacks. Logon events are related to the creation of logon sessions, and they occur on the computer that was accessed. For an interactive logon, events are generated on the computer that was logged on to. For network logon, such as accessing a shared resource, events are generated on the computer that hosts the resource that was accessed. Logoff events are generated when logon sessions are terminated. Note There is no failure ev...
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
