Audit Privilege Use on Windows 2003


i wanting avoid large number of event type 576, 577 , 578 generated in security event log microsoft states events have little or no meaning.

these part of privilege use audit setting.

if i set audit "failures" only, inhibit successful 576, 577 , 578 events or other events inhibited.  if so, can point document defines evetns included under privilege use setting.

thanks

you'll fine not auditing success privilege use.  when enabled, bunch of privileges aren't audited anyway.

joseph durnal



Windows Server  >  Group Policy



Comments

Popular posts from this blog

some help on Event 540

WMI Repository 4GB limit - Win 2003 Ent Question

Event ID 1302 (error 1307) DFS replication service encountered an error while writing to the debug log file