how should I monitor file pemission changes on Windows 2003 servers?

how should I monitor file pemission changes on Windows 2003 servers?
Wich tool/software are reliable?
ZapfoolAsked:
Who is Participating?
I wear a lot of hats...

"The solutions and answers provided on Experts Exchange have been extremely helpful to me over the last few years. I wear a lot of hats - Developer, Database Administrator, Help Desk, etc., so I know a lot of things but not a lot about one thing. Experts Exchange gives me answers from people who do know a lot about one thing, in a easy to use platform." -Todd S.

snoopfroggCommented:
Windows Server 2003 natively allows you to audit permission changes to files and folders.  To do so, you'll need to enable auditing in local security policy or in Group Policy.  You'll need to enable "Audit Policy Change" to audit permission changes:

http://technet.microsoft.com/en-us/library/cc781549(WS.10).aspx

Then, you'll need to enable auditing in the security settings for the file(s) and/or folder(s) you want to audit.
0
ZapfoolAuthor Commented:
Thanks snoopfrogg but my question was not clear enough.
The point is how to parse/sort hunderds of thoussands events in a large environment? (+2000 Windows Servers). Audit department is complaining because there are too many system administrators and if someone change permission on a file or delete a file (boot.ini) nobody is able to figure out who did it.

0
snoopfroggCommented:
Systems Center Operations Manager has an audit collation feature called Audit Collection Services:  http://www.microsoft.com/systemcenter/operationsmanager/en/us/default.aspx.  

GFI Events Manager is an audit collation package that lets you view audit logs from a central location:  http://www.gfi.com/eventsmanager.  

Whichever route you go, you'll need to plan for a management server, backend server, and plan for plenty of storage (depending on the size of your environment, of course).
0
ZapfoolAuthor Commented:
Thanks a lot Snoopfrogg  for your prompt answer. You confirmed my thoughts. We need an extra infra dedicated to perform this heavy task using products such MOM2007. As NetIQ Security Manager is already implemented in the company, it might be a good idea to extend porduct with NetIQ Change Guardian for Windows. I did not know GFI Event Manager product and I'll have a look. I saw also a product called NetVision that could do the job.

My first feeling was that is not so easy to put a "home made" solution by scripting stuffs and you confirmed it.

Bye
0

Experts Exchange Solution brought to you by

Your issues matter to us.

Facing a tech roadblock? Get the help and guidance you need from experienced professionals who care. Ask your question anytime, anywhere, with no hassle.

Start your 7-day free trial
It's more than this solution.Get answers and train to solve all your tech problems - anytime, anywhere.Try it for free Edge Out The Competitionfor your dream job with proven skills and certifications.Get started today Stand Outas the employee with proven skills.Start learning today for free Move Your Career Forwardwith certification training in the latest technologies.Start your trial today
OS Security

From novice to tech pro — start learning today.