Want to win a PS4? Go Premium and enter to win our High-Tech Treats giveaway. Enter to Win

x
?
Solved

Auditing domain admin's actions on exchange/OWA  settings

Posted on 2006-06-27
4
Medium Priority
?
259 Views
Last Modified: 2013-12-04
I have a domain admin that I suspect is chaning things on exchange and OWA (on the same server).  Long story short.  I fixed the issue with only having to enter in username and password only in OWA instead of domain\username.  This worked fine for quite a while until I brought up this fix in a meeting. The admin in question said it wouldn't stay fixed and wanted to implement forms based authentication. (we're not ready to go that way yet, eventually we will). Not more than an hour later, it "mysteriously" reverted back to domain\username in OWA.  

How would I go about auditing any changes made to the network, exchange, and any other servers, when the admin is logged on? I really need some help on this and fast.

thanks
0
Comment
Question by:cknoderer
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 3
4 Comments
 
LVL 38

Accepted Solution

by:
Rich Rumble earned 2000 total points
ID: 16996040
You should turn off the event logging levels, you can access them with secpol.msc or use AD to apply the logging level changes.
http://technet2.microsoft.com/WindowsServer/en/Library/5a86ab0f-c7eb-45ed-9e5e-514173bf15e31033.mspx
You can goto start>run... and type secpol.msc on the run line, then when that window opens goto Local Policies > Audit policy, and start changing the logging of sucess's or failures.
You can employ tools that can alert you to certain events that occur, there are free and paid tools for this.
Free: Snare http://www.intersectalliance.com/projects/SnareWindows/
Pay: GFI SELM http://gfi.com/lanselm/
Those tools will also serve as a backup of the log's, should someone erase them or modify them.
There are others, these two I like very much.
-rich
0
 
LVL 38

Expert Comment

by:Rich Rumble
ID: 16996064
Geez... what a typo... I meant to say, you should turn UP event logging, not off...
-rich
0
 
LVL 1

Author Comment

by:cknoderer
ID: 17009748
Thanks. I will try out the snare program.  I want to nail this weasel to the wall.
0
 
LVL 38

Expert Comment

by:Rich Rumble
ID: 17009782
M$ doesn't keep track of IP's but does use machine names. You may consider using the firewall in 2003 to log ip's, or getting a firewall like zonealarm pro that can also log access via ip.
-rich
0

Featured Post

Automating Your MSP Business

The road to profitability.
Delivering superior services is key to ensuring customer satisfaction and the consequent long-term relationships that enable MSPs to lock in predictable, recurring revenue. What's the best way to deliver superior service? One word: automation.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Many people tend to confuse the function of a virus with the one of adware, this misunderstanding of the basic of what each software is and how it operates causes users and organizations to take the wrong security measures that would protect them ag…
OfficeMate Freezes on login or does not load after login credentials are input.
Visualize your data even better in Access queries. Given a date and a value, this lesson shows how to compare that value with the previous value, calculate the difference, and display a circle if the value is the same, an up triangle if it increased…
Sometimes it takes a new vantage point, apart from our everyday security practices, to truly see our Active Directory (AD) vulnerabilities. We get used to implementing the same techniques and checking the same areas for a breach. This pattern can re…
Suggested Courses

596 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question