Want to win a PS4? Go Premium and enter to win our High-Tech Treats giveaway. Enter to Win

x
?
Solved

how should I monitor file pemission changes on Windows 2003 servers?

Posted on 2009-07-07
4
Medium Priority
?
182 Views
Last Modified: 2013-12-04
how should I monitor file pemission changes on Windows 2003 servers?
Wich tool/software are reliable?
0
Comment
Question by:Zapfool
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 2
  • 2
4 Comments
 
LVL 11

Expert Comment

by:snoopfrogg
ID: 24793807
Windows Server 2003 natively allows you to audit permission changes to files and folders.  To do so, you'll need to enable auditing in local security policy or in Group Policy.  You'll need to enable "Audit Policy Change" to audit permission changes:

http://technet.microsoft.com/en-us/library/cc781549(WS.10).aspx

Then, you'll need to enable auditing in the security settings for the file(s) and/or folder(s) you want to audit.
0
 

Author Comment

by:Zapfool
ID: 24794048
Thanks snoopfrogg but my question was not clear enough.
The point is how to parse/sort hunderds of thoussands events in a large environment? (+2000 Windows Servers). Audit department is complaining because there are too many system administrators and if someone change permission on a file or delete a file (boot.ini) nobody is able to figure out who did it.

0
 
LVL 11

Expert Comment

by:snoopfrogg
ID: 24794383
Systems Center Operations Manager has an audit collation feature called Audit Collection Services:  http://www.microsoft.com/systemcenter/operationsmanager/en/us/default.aspx.  

GFI Events Manager is an audit collation package that lets you view audit logs from a central location:  http://www.gfi.com/eventsmanager.  

Whichever route you go, you'll need to plan for a management server, backend server, and plan for plenty of storage (depending on the size of your environment, of course).
0
 

Accepted Solution

by:
Zapfool earned 0 total points
ID: 24801431
Thanks a lot Snoopfrogg  for your prompt answer. You confirmed my thoughts. We need an extra infra dedicated to perform this heavy task using products such MOM2007. As NetIQ Security Manager is already implemented in the company, it might be a good idea to extend porduct with NetIQ Change Guardian for Windows. I did not know GFI Event Manager product and I'll have a look. I saw also a product called NetVision that could do the job.

My first feeling was that is not so easy to put a "home made" solution by scripting stuffs and you confirmed it.

Bye
0

Featured Post

When ransomware hits your clients, what do you do?

MSPs: Endpoint security isn’t enough to prevent ransomware.
As the impact and severity of crypto ransomware attacks has grown, Webroot fought back, not just by building a next-gen endpoint solution capable of preventing ransomware attacks but also by being a thought leader.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Container Orchestration platforms empower organizations to scale their apps at an exceptional rate. This is the reason numerous innovation-driven companies are moving apps to an appropriated datacenter wide platform that empowers them to scale at a …
OfficeMate Freezes on login or does not load after login credentials are input.
In this video you will find out how to export Office 365 mailboxes using the built in eDiscovery tool. Bear in mind that although this method might be useful in some cases, using PST files as Office 365 backup is troublesome in a long run (more on t…
This lesson discusses how to use a Mainform + Subforms in Microsoft Access to find and enter data for payments on orders. The sample data comes from a custom shop that builds and sells movable storage structures that are delivered to your property. …
Suggested Courses

609 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question