Ways to enable File Server Auditing on Windows Machines

811 Words2 Pages

File Server auditing lets the auditor to trace the secrets hidden beneath the walls of logs. This gives a precise and clear idea who had exactly accessed a file/folder, what changes s/he had made, when, and from where. In addition, the in-depth auditing lets the auditor create the long trails of any change and give an idea about its impact in the future. Not only they can prepare an action plan to revert the undesired changes but they also get equipped to notify and fight with the unauthorized access to the file server. In this post, we’ll discuss the benefits of auditing a file server and the ways to start it on a normal desktop and a Windows Server. Benefits of File Server Auditing Bringing out the secrets File Server logs clearly reveals the access of the users and the changes they’ve made while using the files and folders. This will strengthen them to prove the charges levied against a user for deleting an important file, accessing cryptographic key file meant for account information, or modifying a document. Highlighting the intrusion The auditor can crosscheck the accesses/changes to the file servers at different moments and highlights the unauthorized access. Such an access can be made inside and outside the organization. Keeping an eye on the system files gives an idea about the virus or malware attacks as well. Securing the System Getting the information on time regarding an unauthorized change or a malicious access to the system files, the administrators can take precautionary steps from saving the file server from unwanted situations. Using PowerShell and CMDlets, they can generate the reports manually to highlight such undesired changes and take preventive steps to avoid any kind of irreparable loss. Forensic Investig... ... middle of paper ... ...ings” for the selected file/folder. 3. Go to “Auditing” tab and click “Add” button. This will display the following dialog box to select a user, computer or group. Figure: “Select User, Computer or Group” dialog box 4. Enter the name of users that you want to monitor and click “Check Names” button. 5. Once you’re done then click “OK” button. This will show the following dialog box. Figure: Auditing dialog box 6. Select all the access attributes and their both values “Successful” and “Failed”. 7. Select “Apply these auditing entries to objects and/or containers within this container only”. 8. Click “OK” button. Conclusion File Server Auditing helps a lot in identifying the accesses to the files and let the auditor to highlight the intrusions, if any. In addition, it’s quite simple to follow the above mentioned steps to enable the auditing on the Windows machines.

More about Ways to enable File Server Auditing on Windows Machines

Open Document