Improve company productivity with a Business Account.Sign Up

x
  • Status: Solved
  • Priority: Medium
  • Security: Public
  • Views: 489
  • Last Modified:

system account changing group policy settings

We use Netwrix to report Group Policy changes and have noticed every few weeks the system account is responsible for changing the 'Audit directory service access' setting  under Computer Configuration (Enabled)/Windows Settings/Security Settings/Local Policies/Audit Policy to No auditing.  Is there a legitimate reason that this would be happening?
 netwrix
0
dstewart69
Asked:
dstewart69
  • 2
1 Solution
 
Netman66Commented:
No, this isn't normal behaviour.

Does it ever change back with the System account?

What OS is running on your DCs?

In Server 2008 there is a new subcategory for Directory Service Changes that *might* turn off the legacy setting you have if it is configured, but I don't know if you have a mix of 2003 and 2008 DCs.

You might be able to use Auditpol.exe to see additional details.  This tool also has the ability to modify audit policies, so be careful.

0
 
dstewart69Author Commented:
We have been manually changing it back.
We have just recentely added a 2008 DC but this was happening before that.
I will try the Auditpol.exe and see if I can get any more info.
0
 
dstewart69Author Commented:
No good answer, will just keep manually changing back
0
Question has a verified solution.

Are you are experiencing a similar issue? Get a personalized answer when you ask a related question.

Have a better answer? Share it in a comment.

Join & Write a Comment

Featured Post

Easily Design & Build Your Next Website

Squarespace’s all-in-one platform gives you everything you need to express yourself creatively online, whether it is with a domain, website, or online store. Get started with your free trial today, and when ready, take 10% off your first purchase with offer code 'EXPERTS'.

  • 2
Tackle projects and never again get stuck behind a technical roadblock.
Join Now