Click here to get back home

Setting Audit from CLI

 HomeNewsGroups | Search | About
 microsoft.public.windows.server.security    Post an article   get this group's latest topics as an RSS feed add this group's latest topics to your My MSN content add this group's latest topics to your My Yahoo content
Subject Author Date
Setting Audit from CLI Special Access 03-06-2007
Posted by Special Access on March 6, 2007, 8:42 pm
Please log in for more thread options
Is it possible to set up auditing on files from the command line? Our
installation of W2k3 server is all scripted, but we can't seem to get
the auditing to set properly. We can get it to set on C and some of
the subdirectories by telling the template to pass the audit setting
down to all inherited, but for whatever reason MS decided to really
break up the inheritance in several other directories (like D&S,
Program files and especially Windows)

Thanks!
Mike

Posted by Roger Abell [MVP] on March 8, 2007, 10:23 am
Please log in for more thread options
1) Use secedit to apply a template
To form the template, when you save it from the templates snapin
there will be a dacl and sacl, but you may use text editor to remove
the dacl (D part) so that the template will apply only the sacl
2) Get xcacls.vbs (note: .vbs) from microsoft.com/downloads
This only handles DACLs, but the syntax is effectively the same
so this examples everything you can do to a dacl, and you only
need to alter coded sampled from it slightly to target sacls instead
3) IIRC SetAcl obtainable at sourceforge.net can manipulate sacls

I do agree with the difficulties you mention when forming a filesystem
lockdown due to the way MS has shipped the dacl'ing on Windows.
However, IIRC the sacl'ing inheritance is separate from for dacl
(it is in the dacl or sacl, not in the header part of the sd).

> Is it possible to set up auditing on files from the command line? Our
> installation of W2k3 server is all scripted, but we can't seem to get
> the auditing to set properly. We can get it to set on C and some of
> the subdirectories by telling the template to pass the audit setting
> down to all inherited, but for whatever reason MS decided to really
> break up the inheritance in several other directories (like D&S,
> Program files and especially Windows)
>
> Thanks!
> Mike



Similar ThreadsPosted
Setting Audit Permissions Differently for Each User December 26, 2006, 3:12 pm
How to Audit windows 2003 folder secrity setting change? January 5, 2006, 10:13 pm
Setting up IIS 6.0 tutorial February 21, 2006, 4:38 pm
Setting up LDAPS July 11, 2007, 2:41 pm
setting up 2-Tier CA Environment July 14, 2005, 3:36 pm
question on setting security November 9, 2006, 10:20 pm
hardcoding DC IP address for network setting. July 12, 2005, 10:42 am
Help setting Windows permissions (policy?) April 26, 2006, 1:06 pm
Problem setting the "Valid To" for EFS certificates July 5, 2006, 9:57 am
Setting COM Security at the parent levels November 7, 2006, 10:01 am

Our other projects:

Art Dolls, Fairies and Mermaids - Sunnyfaces.net

Roy's Linux, Programming and Search Engines messages

1-Script XML SitemapXML Sitemap