Click here to get back home

auditing user access

 HomeNewsGroups | Search | About
 microsoft.public.windows.server.security    Post an article   get this group's latest topics as an RSS feed add this group's latest topics to your My MSN content add this group's latest topics to your My Yahoo content
Subject Author Date
auditing user access cpu 09-13-2007
Posted by cpu on September 13, 2007, 8:37 am
Please log in for more thread options
How do I go about auditing users on the network? We have file servers,
database servers and web application servers. The last time I enabled
auditing for logons, object and file access, it generated a mess of output
in the Event Viewer Security log that was basically indecipherable... in
other words, it was useless.

Are there any commercial tools for Windows that allow a sysadmin to see
when a user logs on what objects (files,printers,servers he accesses? A
single entry for each user and each object.

The act of logging on and accessing a single file on a system generates
hundreds of events in the Windows Event Viewer Security log... which is
next to impossible to read.

BTW, how would you prevent privilege escalation? Use 2 factor
authentication?


The company I work for has been audited. I've been asked to look in to the
following risk area

<quote>
Risk Area:
Lack of audit log of privileged user activities and contrls to prevent
privilege escalation on critical systems

Observation:
There is no control to prevent privilege escalation if user has knowledge
of the system admin password. Furthermore, user accountability can not be
established without user activity audit logs"

Improvement Opportunity:
Use system function / tools to prevent privilege escalation and establish
user activity accountability
</quote>

What's the point of preventing privilege escalation? If you've been given
the privilege to do something, and its prevented, then you don't have the
privilege at all... huh?

Posted by jwgoerlich on September 13, 2007, 9:25 am
Please log in for more thread options
I will let someone else address the question on commercial auditing
tools. (I am interested in that answer myself.)

Regarding your audit, the privilege escalation in this sense means
logging on as one user account and then launching a process as the
administrator (runas or sudo). Mitigating controls include: limit
knowledge of the administrator password to one individual (and
possibly keeping a copy in a sealed envelop in a safe); audit all
login activity; set the NTFS ACL on %systemroot%\system32\runas.exe to
restrict its use to those with a business need.

Hope that helps and good luck on the audit,

J Wolfgang Goerlich

>
> <quote>
> Risk Area:
> Lack of audit log of privileged user activities and contrls to prevent
> privilege escalation on critical systems
>
> Observation:
> There is no control to prevent privilege escalation if user has knowledge
> of the system admin password. Furthermore, user accountability can not be
> established without user activity audit logs"
>
> Improvement Opportunity:
> Use system function / tools to prevent privilege escalation and establish
> user activity accountability
> </quote>
>
> What's the point of preventing privilege escalation? If you've been given
> the privilege to do something, and its prevented, then you don't have the
> privilege at all... huh?



Similar ThreadsPosted
Auditing File Access January 15, 2008, 11:18 am
Auditing user OU Changes February 14, 2008, 11:48 am
Auditing what a user does -possible software ideas. April 9, 2008, 6:24 am
File Access Auditing on Exchange 2003 Server June 28, 2005, 4:01 am
How Do We Avoid Auditing Failed SYNCHRONIZE File Access? July 4, 2006, 1:36 am
user cannot access shares October 21, 2005, 12:30 pm
Re: user cannot access shares October 25, 2005, 10:23 pm
Drive access to particular user December 3, 2006, 7:54 am
Moved User Files - Now No Access July 18, 2006, 5:35 pm
Can I restric the access to information on user in the AD August 10, 2006, 12:12 pm

Our other projects:

Art Dolls, Fairies and Mermaids - Sunnyfaces.net

Roy's Linux, Programming and Search Engines messages

1-Script XML SitemapXML Sitemap