Solved

logon success and failure auditing

Posted on 2013-11-11
4
419 Views
Last Modified: 2013-11-20
Can anyone elaborate on the risk on not enabling logon success and failure auditing on file servers? Our admin doesnt enable auditing for such events and doesnt see it as a risk - as its only a select few IT admins who could ever logon anyway, so doesnt see what value such auditing would bring. Can anyone give a good example where logon success and failure would be required - and issues that could arise by not enabling logon success or failure.
0
Comment
Question by:pma111
  • 2
4 Comments
 
LVL 21

Expert Comment

by:RK
ID: 39638166
Hi,

This is the best practice for security audits http://technet.microsoft.com/en-us/library/cc778162(v=ws.10).aspx

You can use this link to configure security audits http://technet.microsoft.com/en-us/library/dd277403.aspx
0
 
LVL 3

Author Comment

by:pma111
ID: 39638172
Thats not really the question though - the question is what is the risk in not enabling auditing - when will it come back to haunt you.
0
 
LVL 21

Accepted Solution

by:
RK earned 250 total points
ID: 39638179
Risk - You can not find out users who has logged in and out successfully on the domain.

You will not be able to find out user's / Computer's in case of major virus attack either from client or server.

Mapped drive access - You can not identify who is accessing the shares.

You will not be able to see if any modification happened on the server, I.e - Somebody changed the server time.

There are plenty of risk factors for not enabling security audits.

Hope this clarify your query
0
 
LVL 2

Assisted Solution

by:daniel0
daniel0 earned 250 total points
ID: 39638509
At the AD enabling the auditing is not a risk to be get in. Its like up to your requirment that satisfy the need of your auditing. Moreover enabling the auditing of Log on and log off is you would able to get an report of all the user who are log in to the system.

There are few applications also who does the same AD auditing work . You can test them to get an idea and complexity about the drawbacks. If in case you are concerend about the issues then only issues that can arrive is about of Replication issues.

Please have a look at this link for the details.

http://technet.microsoft.com/en-us/library/cc949120(v=ws.10).aspx

Thanks.
0

Featured Post

Do email signature updates give you a headache?

Are you constantly making changes to email signatures? Are the images not formatting how you want them to? Want high-quality HTML signatures on all devices, including on mobiles and Macs? Then, let Exclaimer solve all your email signature problems today.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Remote Apps is a feature in server 2008 which allows users to run applications off Remote Desktop Servers without having to log into them to run the applications.  The user can either have a desktop shortcut installed or go through the web portal to…
New Windows 7 Installations take days for Windows-Updates to show up and install. This can easily be fixed. I have finally decided to write an article because this seems to get asked several times a day lately. This Article and the Links apply to…
This tutorial will walk an individual through the steps necessary to configure their installation of BackupExec 2012 to use network shared disk space. Verify that the path to the shared storage is valid and that data can be written to that location:…
This tutorial will walk an individual through configuring a drive on a Windows Server 2008 to perform shadow copies in order to quickly recover deleted files and folders. Click on Start and then select Computer to view the available drives on the se…

911 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

17 Experts available now in Live!

Get 1:1 Help Now