Auditing Folder Ownership Changes on Windows Server 2008

How can I find the cause of a folder's Ownership changing from a particular user, say "Joe", to the Administrators Group. The folder, called Test, is on a Windows Server 2008 r2 server and the path looks like the following:


Note: Inheritable permissions is unchecked on Test, so only explicit permissions apply on this folder.

When auditing, will default logging be able to find the cause or do I have to turn on special logging to enable this kind of auditing?
Who is Participating?
Michael PfisterCommented:
Turn on auditing

Select the Administrator group and audit "Take ownership" "Success"

Manpreet SIngh KhatraSolutions Architect, Project LeadCommented:
What's New in Windows Security Auditing

There are a number of auditing enhancements in Windows Server® 2008 R2 and Windows® 7 that increase the level of detail in security auditing logs and simplify the deployment and management of auditing policies. These enhancements include:
Global Object Access Auditing
"Reason for access" reporting
Advanced audit policy settings

In order to track file and folder access on Windows Server 2008 R2

- Rancy
btanExec ConsultantCommented:
To audit files and directories on a particular server, the File and Object Access audit event option must be enabled in the Audit Policy for that server. I believe the event that you should be looking for are below. It should be configured in Global Object Access Auditing Group Policy setting. Pls see this  @


>>  EventID 4670 - Permissions on an object were changed.
- Logged when anyone changes the DACL (Discretionary Access Control List) on a file, folder, or securable object.
>>  EventID 4907 - Auditing settings on object were changed.
-  Logged every time an administrator or program changes the SACL (System Access Control List) on an object, typically a file or folder.

For info, every securable object (e.g. file, folder, registry key, etc) in Windows has a Security Descriptor assigned to it. The security descriptor, among other things, specifies:

1.) the user owner of the object
2.) the group of the object (used by Unix apps that run under POSIX)
3.) the DACL (Discretionary Access Control List), and
4.) the SACL (System Access Control List)
CreatedAuthor Commented:
Sorry, I messed up and didn't distribute the points. I wanted to give points to assisted solutions even though the right person was the accepted solution. Will have to be a little more aware next time.
Question has a verified solution.

Are you are experiencing a similar issue? Get a personalized answer when you ask a related question.

Have a better answer? Share it in a comment.

All Courses

From novice to tech pro — start learning today.