﻿<?xml version='1.0' encoding='UTF-8'?><rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/"><channel><title>UltimateWindowsSecurity.com Forum / Ultimate Windows Security Forum / IT Audit / Windows Server </title><generator>InstantForum.NET v4.1.4</generator><description>UltimateWindowsSecurity.com Forum</description><link>http://forum.ultimatewindowssecurity.com/</link><webMaster>noreply@ultimatewindowssecurity.com</webMaster><lastBuildDate>Sat, 31 Jul 2010 02:04:50 GMT</lastBuildDate><ttl>20</ttl><item><title>Auditing Folder Permissions - In detail...</title><link>http://forum.ultimatewindowssecurity.com/Topic413-9-1.aspx</link><description>Hi,&lt;/P&gt;&lt;P&gt;I was wondering if anybody has any pointers on how to do "detailed" folder auditing. I am aware of enable object auditing policies and setting up Change Permission and Take Ownership on the actual folder. I am interested in determining "who" granted/revoked "what" to "whom" and "when".&lt;/P&gt;&lt;P&gt;So if an IT admin grants permission to a folder to a user, I'd like to be able to see the details of that activity in the event log (Windows 2003). I currently see events 560, but this only tells me a DAC was changed... how do I monitor the details of what was changed via the event log and my SIEM?&lt;/P&gt;&lt;P&gt;Thanks!</description><pubDate>Thu, 08 Jul 2010 13:36:03 GMT</pubDate><dc:creator>security.guy</dc:creator></item><item><title>SOD - practically for Windows administrators</title><link>http://forum.ultimatewindowssecurity.com/Topic116-9-1.aspx</link><description>&lt;FONT size=1&gt;Hi,&lt;/FONT&gt;&lt;P&gt;&lt;FONT size=1&gt;During the IT audit I have hit into practical problem asked by auditees - how we can practically organise the segregation of duty in MS Windows environmnet, so that administrators would not have access to top management file server, or i.e. their Exchange mail? Of course, SOD could be applied at least to different roles of admins (MS Exchange v.s. file server admin), but as they often need to be domain admins to do their regular job, I am not sure if chance to take priviledges is not a risk. Of course, turning on audit trail could be a way, but I believe this kind of activity will be under carpet within 6m.&lt;/FONT&gt;&lt;P&gt;&lt;FONT size=1&gt;I was also thinking if ILP (Information leak protection) systems could not help them in this risk control?&lt;/FONT&gt;&lt;P&gt;&lt;FONT size=1&gt;Thanks for any open ideas,&lt;/FONT&gt;&lt;P&gt;&lt;FONT size=1&gt;Jiri&lt;BR&gt;&lt;/FONT&gt;</description><pubDate>Tue, 23 Jun 2009 10:03:54 GMT</pubDate><dc:creator>sulovsky</dc:creator></item><item><title>Should security audit policy ever include the Application and System logs?</title><link>http://forum.ultimatewindowssecurity.com/Topic401-9-1.aspx</link><description>Hello,&lt;br&gt;I know this site seems to be focused on the Security logs.. and for good cause. But, I was wondering if it's ever a good idea to monitor some of the other Windows logs, such as, Application and System?&lt;br&gt;Thanks,&lt;br&gt;Tom&lt;br&gt;</description><pubDate>Tue, 06 Jul 2010 00:48:36 GMT</pubDate><dc:creator>TomMartin</dc:creator></item><item><title>Audit Start &amp; Stop Event for Windows Server (7035 EventID)</title><link>http://forum.ultimatewindowssecurity.com/Topic142-9-1.aspx</link><description>Hello,&lt;br&gt;&lt;br&gt;I search how to setup audit on stop and start events for Windows Service for a member server.&lt;br&gt;Event are generated in system log (7035)</description><pubDate>Fri, 24 Jul 2009 09:03:14 GMT</pubDate><dc:creator>legallf</dc:creator></item><item><title>How to easily obtain Event Log activity metrics</title><link>http://forum.ultimatewindowssecurity.com/Topic84-9-1.aspx</link><description>How much log data and/or how many events is a given server creating in a typical day?  In a typical week?  At its peak moment (Monday morning)?&lt;br&gt;&lt;br&gt;This question is of particular interest for Domain Controllers, and I don't know the answer.  Are there any built-in Windows tools or interfaces for displaying this type of data?  Or any simple (and free) third party tools for doing so?</description><pubDate>Fri, 01 May 2009 17:17:48 GMT</pubDate><dc:creator>ottermaton</dc:creator></item></channel></rss>