Windows IT Pro is the leading independent community for IT professionals deploying Microsoft Windows server and client applications and technologies.
  
  
  Advanced Search 


December 19, 2005

Logging Domain Policy Changes

RSS
Subscribe to Windows IT Pro | See More Security Articles Here | Reprints | Or get the Monthly Online Pass—only $5.95 a month!
Main Article    Access Denied

We use a piece of software to collate and interrogate the Security event logs from domain controllers (DCs) to indicate anyone changing the Audit Policy or Account Policy. In Windows NT, we looked for event ID 612 and event ID 643, respectively. In Windows 2000 Active Directory (AD), we've found that event ID 643 is produced every hour on each DC as Group Policy Objects (GPOs) are applied. Have you come across this problem, and have you found any equivalent events that give an idea of whether anyone is messing with the Audit or Account policies?

I know this is a problem in Windows 2000 until Service Pack 3 (SP3), which fixes it. On Win2K SP2 and earlier, domain controllers (DCs) log event ID 643 only if something about the domain actually changed. Event ID 643 on Windows Server 2003 also specifies the exact policies changed along with their new values.

Figure 1 shows an event ID 643 that a Windows 2003 machine logged when I changed two of the account lockout policies. Typically, event ID 643 identifies the user who changed the policy as the DC itself because administrators indirectly configure domain policies by editing GPOs, which are then applied by Windows.

On Windows 2003, you might come across an event ID 643 that identifies one of the domain administrators as the user but doesn't specify any changed policy values, as Figure 2 shows. I've deduced that this event is the result of the administrator changing the permissions on the root of the domain in Active Directory Users and Computers.

End of Article



Reader Comments
very good

ealyad January 07, 2006 (Article Rating: )


I'd like to know the name of that software that collates security logs too.

michaelsic February 28, 2006 (Article Rating: )


eventsentry is what we use to centralise the alerts into a SQL database but there are many others that can do the job.

mpetre April 21, 2006 (Article Rating: )


good article.

monacos May 17, 2006 (Article Rating: )


yyyyyyyyyyyyyyyyyyy

ravi123 July 21, 2006 (Article Rating: )


You must be a registered user or online subscriber to comment on this article. Please log on before posting a comment. Are you a new visitor? Register now




Top Viewed ArticlesView all articles
WinInfo Short Takes: Week of November 23, 2009

An often irreverent look at some of the week's other news, including some post-PDC some soul searching, a Google Chrome OS announcement and a Microsoft response, Windows 7 off to a supposedly strong start, the Jonas Brothers and Xbox 360, and so much more ...

2009 Windows IT Pro Editors' Best and Community Choice Awards

Picking a favorite product from an impressive crowd of competitive offerings is never an easy task, and such was the case with our Editors' Best and Community Choice awards this year. ...

Command Prompt Tricks

One reader shares his tip for setting up the command prompt to reflect a remote path. ...


Security Whitepapers Reducing the Costs and Risks of Branch Office Data Protection

Solving Desktop Management Challenges in Healthcare

Solving Desktop Management Challenges in Education

Related Events The Easiest Way to Save Time and Money on E-mail and SharePoint Management

Introduction to Identity Lifecycle Manager "2"

SQL Server Security: How to Secure, Monitor & Audit Your Databases

Check out our list of Free Email Newsletters!

Security eBooks Spam Fighting and Email Security for the 21st Century

Understanding and Leveraging Code Signing Technologies

A Guide to Windows Certification and Public Keys

Related Security Resources Introducing Left-Brain.com, the online IT bookstore
Looking for books, CDs, toolkits, eBooks? Prime your mind at Left-Brain.com

Discover Windows IT Pro eLearning Series!
Clear & detailed technical information and helpful how-to's, all in our trademark no-nonsense format


Windows IT Pro Home Register FAQ for Windows WinInfo News
Europe Edition About Us Contact Us/Customer Service Media Kit Affiliates / Licensing  
SQL Server Magazine Office & SharePoint Pro DevProConnections IT Job Hound
Left-Brain.com Technology Resource Directory asp.netPRO ITTV Windows SuperSite 
 
 Windows IT Pro is a Division of Penton Media Inc.
 © 2009 Penton Media, Inc. Terms of Use | Privacy Statement