Click here to get back home

Object Access Failure Audit

 HomeNewsGroups | Search | About
 microsoft.public.windows.server.security    Post an article   get this group's latest topics as an RSS feed add this group's latest topics to your My MSN content add this group's latest topics to your My Yahoo content
Subject Author Date
Object Access Failure Audit Michael D'Angelo 06-12-2006
Posted by Michael D'Angelo on June 12, 2006, 10:37 am
Please log in for more thread options
I turned on failure auditing for everyone on my system drive, and I noticed
there are a number of failed accesses with the flags:

READ_CONTROL
SYNCHRONIZE
ReadData (or ListDirectory)
ReadEA
ReadAttributes
WriteAttributes

Am I correct in interpreting this as failing because the program is
attempting to update the last access time attribute?



Posted by Roger Abell [MVP] on June 13, 2006, 5:24 am
Please log in for more thread options
The accesses requested are what is shown, and a failure event means
that one or more of those was not granted. A plain grant of Read,
which does not include Write Attributes, is sufficient for the filesystem
to allow the file content to be accessed (and have the last accessed
timestamp updated, which is done by the system).
Whatever is attempting the file opens is specifically requesting a
grant that is not allowed by NTFS, probably the Write Attribute.

Roger

>I turned on failure auditing for everyone on my system drive, and I noticed
>there are a number of failed accesses with the flags:
>
> READ_CONTROL
> SYNCHRONIZE
> ReadData (or ListDirectory)
> ReadEA
> ReadAttributes
> WriteAttributes
>
> Am I correct in interpreting this as failing because the program is
> attempting to update the last access time attribute?
>



Similar ThreadsPosted
Object Access failure shows up when users open their own files?? October 2, 2007, 11:33 am
Object Access failure shows up when users open their own files?? October 2, 2007, 11:51 am
Failure audits for object access on logon scripts and startup scripts, but clients still run them fine. February 27, 2008, 7:40 am
Services Security Failure Audit October 29, 2005, 2:09 pm
673 Failure Audit appears several times per day December 10, 2005, 11:46 pm
Meaning of This Failure Audit EventID 560 March 17, 2007, 2:23 am
Sourcing security failure audit id: 529 Windows server 2003 March 7, 2007, 9:14 am
Grant Object Access August 19, 2005, 4:52 pm
Audit file/folder access February 12, 2007, 10:52 am
audit folder access, exclude user November 27, 2007, 5:14 pm

Our other projects:

Art Dolls, Fairies and Mermaids - Sunnyfaces.net

Roy's Linux, Programming and Search Engines messages

1-Script XML SitemapXML Sitemap