﻿<?xml version='1.0' encoding='UTF-8'?><rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/"><channel><title>UltimateWindowsSecurity.com Forum / Ultimate Windows Security Forum / IT Audit / Active Directory </title><generator>InstantForum.NET v4.1.4</generator><description>UltimateWindowsSecurity.com Forum</description><link>http://forum.ultimatewindowssecurity.com/</link><webMaster>noreply@ultimatewindowssecurity.com</webMaster><lastBuildDate>Sat, 31 Jul 2010 02:05:24 GMT</lastBuildDate><ttl>20</ttl><item><title>Auditing for account or group creation priviledge</title><link>http://forum.ultimatewindowssecurity.com/Topic396-8-1.aspx</link><description>How can a user or group access privilege escalation for account or group&lt;br&gt;creation can be audited and reported with the Windows 2003 active directory.&lt;br&gt;&lt;br&gt;Even with all auditing enabled It only shows event id 566 as the only&lt;br&gt;significant event with little info as below. It doesn't display the user or&lt;br&gt;group being granted acccess for and/or access to&lt;br&gt;&lt;br&gt;Accesses: WRITE_DAC&lt;br&gt;&lt;br&gt;Properties:&lt;br&gt;WRITE_DAC&lt;br&gt;&lt;br&gt;Also, in the Webnar "Top 10 Active Directory Changes to Monitor in the Security Log" it is mentioned in the slide for event 565 while it actual is event 566 as shown in the example as well.&lt;br&gt;&lt;br&gt;Thanks &lt;br&gt;Sunil Gupta</description><pubDate>Mon, 28 Jun 2010 09:31:57 GMT</pubDate><dc:creator>SGupta</dc:creator></item><item><title>Auditing Password Length</title><link>http://forum.ultimatewindowssecurity.com/Topic399-8-1.aspx</link><description>We require that Windows/Active Directory passwords for certain sensitive accounts be a minimum length of 15 characters.  &lt;P&gt;&lt;FONT size=2&gt;I've noticed that L0phtcrack is able to very rapidly detect when an account's password is greater than 14 characters.  Are there any other tools that can do that quickly and, preferably, be automated to scan through entire forests?  Any that can report actual length?&lt;/FONT&gt;</description><pubDate>Thu, 01 Jul 2010 10:22:27 GMT</pubDate><dc:creator>jlashnits</dc:creator></item><item><title>Microsoft Security Update Testing</title><link>http://forum.ultimatewindowssecurity.com/Topic356-8-1.aspx</link><description>Hello, &lt;/P&gt;&lt;P&gt;For Patch Tuesday :w00t: where Testing is required, &lt;/P&gt;&lt;P&gt;I would like to know how do &lt;STRONG&gt;you&lt;/STRONG&gt; go about testing them ? :doze:&lt;/P&gt;&lt;P&gt;What do you recommend for our test labs ? :unsure:&lt;/P&gt;&lt;P&gt;How to make a complete testing environment ? :cool:&lt;/P&gt;&lt;P&gt;&lt;U&gt;&lt;FONT color=#dd11dd&gt;&lt;STRONG&gt;Renji George&lt;/STRONG&gt;&lt;/FONT&gt;&lt;/U&gt;&lt;/P&gt;&lt;P&gt;&lt;BR&gt; </description><pubDate>Thu, 15 Apr 2010 18:30:34 GMT</pubDate><dc:creator>renji</dc:creator></item><item><title>Privileged access</title><link>http://forum.ultimatewindowssecurity.com/Topic335-8-1.aspx</link><description>What logged events could be used to indicate that a new Active Directory group has been added that has Domain Admin equivalent access?  In theory, a group could be added that's called "Inquiry" and is given Full Control to everything in the domain - is there a logged event or series of logged events that could identify this activity?  Certainly the naming convention is not useful in this example...</description><pubDate>Tue, 16 Mar 2010 11:18:07 GMT</pubDate><dc:creator>kkscfb</dc:creator></item><item><title>Audit Windows 2008 File Shares</title><link>http://forum.ultimatewindowssecurity.com/Topic321-8-1.aspx</link><description>I have a 3 node Windows 2008 cluster that has most of our file shares. Someone is making changes to share\folder\file permissions that is causeing me a lot of problems. I am trying to figure out the best way to audit who is making the changes.&lt;/P&gt;&lt;P&gt;I have SCOM 2007 R2 in my environment, so I can also utilize that to report on who is making changes.&lt;/P&gt;&lt;P&gt;Please help!!!</description><pubDate>Sat, 27 Feb 2010 18:55:57 GMT</pubDate><dc:creator>dvdkea</dc:creator></item><item><title>Event ID for modified GPOs</title><link>http://forum.ultimatewindowssecurity.com/Topic315-8-1.aspx</link><description>I have to know, who (usersid or loginname) changed a specified GPO for a specified OU in the Active Directory. Given our audit settings include this, what would be the right Event ID to look for?</description><pubDate>Mon, 22 Feb 2010 04:16:19 GMT</pubDate><dc:creator>hinek</dc:creator></item><item><title>Difference between Admin group and domain admin group in AD</title><link>http://forum.ultimatewindowssecurity.com/Topic292-8-1.aspx</link><description>Can anyone describe the difference between the AD groups admin and domain admin?  Can the AD admin group do just as much, security wise, as the domain admin group?</description><pubDate>Tue, 29 Dec 2009 12:26:33 GMT</pubDate><dc:creator>duketter</dc:creator></item><item><title>AZMAN (Authorization Manager) Events</title><link>http://forum.ultimatewindowssecurity.com/Topic137-8-1.aspx</link><description>Hi, &lt;/P&gt;&lt;P&gt;I'd loke to know how to implement Azman Audit. I recently enable the audit in Authorization manager, but I didn't receive any event in the security Log.&lt;/P&gt;&lt;P&gt;I also check that "Directory Service Access" is enabled in AD as Microsoft recommends, but nothing happens.&lt;/P&gt;&lt;P&gt;Any Idea?&lt;/P&gt;&lt;P&gt;Thanks.</description><pubDate>Mon, 20 Jul 2009 14:26:28 GMT</pubDate><dc:creator>pstamati</dc:creator></item><item><title>Logging computer moves between OU's</title><link>http://forum.ultimatewindowssecurity.com/Topic174-8-1.aspx</link><description>What auditing events or other dependencies must be enabled to record these issues:&lt;/P&gt;&lt;P&gt;1.  when a computer account is moved between OU's?  &lt;/P&gt;&lt;P&gt;2.  when GPO's are applied or removed from computer accounts</description><pubDate>Thu, 13 Aug 2009 15:31:38 GMT</pubDate><dc:creator>des2009</dc:creator></item></channel></rss>