Solved

Service connection point Object creation/deletion is not audited in Active Directoty

Posted on 2014-03-31
5
74 Views
Last Modified: 2015-06-24
Hi,
I am trying to audit creation/deletion/update of service connection point type objects in an specific OU and sub OU's in AD. Attached is the snapshot of audit policy I have applied on OU. But I do not see any events in security events log on the DC. Can any one tell me what I am doing wrong or what else needs to be done to enable audit on all object in certain OU in AD?
Policy.JPG
0
Comment
Question by:SRao123
  • 2
5 Comments
 
LVL 35

Accepted Solution

by:
Mahesh earned 500 total points
ID: 39966030
What your screen shot showing is you have enabled auditing of file folder access

If you wanted to audit SCP related changes, then you must enable Audit directory service access for failure and success in default domain controller policy, then it will populate logs in security event logs on DC server

Also you will get some information in Directory service event logs on domain controller

Mahesh.
0
 
LVL 1

Author Comment

by:SRao123
ID: 39966043
We have DS auditing on success enabled, as in attached snapshot. Will that be enough or we need to make some other changes?
policy2.JPG
0
 
LVL 35

Expert Comment

by:Mahesh
ID: 39966194
That right
You need to select failure as well
0
 
LVL 34

Expert Comment

by:Seth Simmons
ID: 40848205
This question has been classified as abandoned and is closed as part of the Cleanup Program. See the recommendation for more details.
0

Featured Post

PRTG Network Monitor: Intuitive Network Monitoring

Network Monitoring is essential to ensure that computer systems and network devices are running. Use PRTG to monitor LANs, servers, websites, applications and devices, bandwidth, virtual environments, remote systems, IoT, and many more. PRTG is easy to set up & use.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

Resolve DNS query failed errors for Exchange
In this article, we will see the basic design consideration while designing a Multi-tenant web application in a simple manner. Though, many frameworks are available in the market to develop a multi - tenant application, but do they provide data, cod…
This tutorial will give a an overview on how to deploy remote agents in Backup Exec 2012 to new servers. Click on the Backup Exec button in the upper left corner. From here, are global settings for the application such as connecting to a remote Back…
This tutorial will walk an individual through the process of transferring the five major, necessary Active Directory Roles, commonly referred to as the FSMO roles to another domain controller. Log onto the new domain controller with a user account t…

914 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

18 Experts available now in Live!

Get 1:1 Help Now