Click here to get back home

How do I monitor file access rights on Win2003?

 HomeNewsGroups | Search | About
 microsoft.public.windows.server.security    Post an article   get this group's latest topics as an RSS feed add this group's latest topics to your My MSN content add this group's latest topics to your My Yahoo content
Subject Author Date
How do I monitor file access rights on Win2003? dlu 05-19-2006
Posted by dlu on May 19, 2006, 2:20 am
Please log in for more thread options
I would like to get notified, or at least have a reasonable logfile of
changes in the access rights on a Win2003 file share.

As far as I see it, the Event Log does not do what I like. If I set the
server to monitor the access right, I can see that something happened,
but I do not see what has been changed. Also, the Event Log and all the
tools that use it show way too much information.

What I need is a report that looks like this (Looks better with fixed
width font):
USER OBJECT TIMESTAMP
NEW ACCESS RIGHTS
------------ ------------------------ -------------------
--------------------------------------------------------------------

mydomain\mrx d:\netshare\dir01 2006-05-18-08:10:10
read, write for all domain users, full access for mydomain\mry, read
for guests

mydomain\mry d:\netshare\dir02\file01 2006-05-18-08:10:10
read, write for all domain users, read for guests

Is there any way I can Windows persuade to do this?
Are there maybe Tools which can perform this Task?

Thanx a lot in advance!


Posted by Roger Abell [MVP] on May 19, 2006, 9:12 am
Please log in for more thread options
To get audit information logged about NTFS objects you need to
both enable auditing of object access and also set the SACL (the
Audit tab in the NTFS security dialog) on what should be subjected
to the auditing. This SACL states what actions should trigger an
audit record being cut, which in your scenario would be success
for the permission to change permissions.

>I would like to get notified, or at least have a reasonable logfile of
> changes in the access rights on a Win2003 file share.
>
> As far as I see it, the Event Log does not do what I like. If I set the
> server to monitor the access right, I can see that something happened,
> but I do not see what has been changed. Also, the Event Log and all the
> tools that use it show way too much information.
>
> What I need is a report that looks like this (Looks better with fixed
> width font):
> USER OBJECT TIMESTAMP
> NEW ACCESS RIGHTS
> ------------ ------------------------ -------------------
> --------------------------------------------------------------------
>
> mydomain\mrx d:\netshare\dir01 2006-05-18-08:10:10
> read, write for all domain users, full access for mydomain\mry, read
> for guests
>
> mydomain\mry d:\netshare\dir02\file01 2006-05-18-08:10:10
> read, write for all domain users, read for guests
>
> Is there any way I can Windows persuade to do this?
> Are there maybe Tools which can perform this Task?
>
> Thanx a lot in advance!
>



Posted by dlu on May 22, 2006, 2:00 am
Please log in for more thread options
Thanks, but that does not get me the result I would like to have. The
best entry I can see the looks like this (Sorry, but it is in German):

*********************************************************
Ereignistyp:        Erfolgs=FCberw.
Ereignisquelle:        Security
Ereigniskategorie:        Objektzugriff
Ereigniskennung:        560
Datum:                19.05.2006
Zeit:                16:59:44
Benutzer:                *DOMAIN\USER*
Computer:        *HOSTNAME*
Beschreibung:
Ge=F6ffnetes Objekt:
        Objektserver:        Security
        Objekttyp:        File
        Objektname:        *FILENAME*
        Handlekennung:        1680
        Vorgangskennung:        
        Prozesskennung:        3324
        Abbilddateiname:        C:\WINDOWS\explorer.exe
        Prim=E4rer Benutzername:        *USER*
        Prim=E4re Dom=E4ne:        *DOMAIN*
        Prim=E4re Anmeldekennung:        (0x0,0x.......)
        Clientbenutzername:        -
        Clientdom=E4ne:        -
        Clientanmeldekennung:        -
        Zugriffe:        READ_CONTROL
                        WRITE_DAC
                        Attribute lesen

        Rechte:        -
        Beschr=E4nkte SID-Anzahl:        0
        Zugriffsmaske:        0x60080


Weitere Informationen =FCber die Hilfe- und Supportdienste erhalten Sie
unter http://go.microsoft.com/fwlink/events.asp.
*********************************************************

So I know who wanted to change which file at which time.
Problem 1: I only get to know that the permission for changing
permission has been granted. I do not know if the permission actually
got changed. Not very good, but I colud live with that.
Problem 2: I do not know how the permissions got changed. Did the user
add another user/group? Did the user grant more permissions or did he
revoke some? I have no idea!

I tried to solve problem no. 2, but unfortunately that is not as
trivial as I first thought. If I try to scan the file right after the
rights have been changed I can see the new status of the rights. Since
I haven't figured out a way to see who changed the file, I have to
match it with the Event Log. This works fine in the beginning, but once
the Log reaches a certain size, it takes too long to scan it for the
matching entry. Especially if someone changed permissions on a folder
that includes many subfolders and files.


Similar ThreadsPosted
Monitor File Access February 12, 2007, 12:09 pm
Monitor Access To A Particular Share September 1, 2005, 8:25 am
Monitor Access To A Particular Share February 18, 2007, 6:07 pm
Win2003 R2: Permission to file is different from what was granted September 25, 2007, 5:08 am
file server move from win2000 to win2003 April 24, 2008, 9:50 pm
Bizarre File Security Issue in Win2003 server January 12, 2006, 9:50 am
Changing local file rights July 27, 2005, 11:00 am
File Access Audit on File Server June 20, 2007, 4:59 pm
after win2000 upgrade to win2003,event log can not access March 9, 2006, 3:57 am
How to set different USB access privileges in Win2K\WinXP\Win2003 March 15, 2008, 9:20 pm

Our other projects:

Art Dolls, Fairies and Mermaids - Sunnyfaces.net

Roy's Linux, Programming and Search Engines messages

1-Script XML SitemapXML Sitemap