WindowsXP-SP1/admin/admt/documents/help-ms/admtsetw2kauditing.htm
2020-09-30 16:53:49 +02:00

62 lines
2.7 KiB
HTML

<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.0//EN"
"http://www.w3.org/TR/REC-html40/strict.dtd">
<HTML DIR="LTR">
<HEAD>
<TITLE>Enable auditing on a Windows&nbsp;2000 domain</TITLE>
<LINK REL="stylesheet" MEDIA="screen" TYPE="text/css" HREF="coUA.css">
<LINK REL="stylesheet" MEDIA="print" TYPE="text/css" HREF="coUAprint.css">
<SCRIPT LANGUAGE="JScript" SRC="shared.js"></SCRIPT>
<META HTTP-EQUIV="Content-Type" CONTENT="text-html;charset=Windows-1252">
<META HTTP-EQUIV="PICS-Label" CONTENT='(PICS-1.1 "<http://www.rsac.org/ratingsv01.html>" l comment "RSACi North America Server" by "inet@microsoft.com <mailto:inet@microsoft.com>" r (n 0 s 0 v 0 l 0))'>
<META NAME="MS.LOCALE" CONTENT="EN-US">
<META NAME="MS-IT-LOC" Content="Active Directory Migration Tool">
<META NAME="MS-HAID" CONTENT="a_ADMTSetW2KAuditing">
</HEAD>
<BODY>
<P CLASS="procLabel">To enable auditing on a Windows&nbsp;2000 domain</P>
<OL>
<LI>On a computer with administrative access to the Windows&nbsp;2000 domain, click <B>Start</B>, point to <B>Programs</B>, point to <B>Administrative Tools</B>, and then click <B>Active Directory Users and Computers</B>.</LI>
<LI>In the console tree, right-click <B>Domain Controllers</B>, and then click <B>Properties</B>.</LI>
<LI>On the <B>Group Policy</B> tab , click <B>Default Domain Controller Policy</B>, and then click <B>Edit</B>.</LI>
<LI>In the <B>Group Policy</B> console tree, double-click <B>Audit policies</B>.
<P CLASS="navTree"><A ID="expand" HREF="#" CLASS="where">Where?</A></P>
<DIV CLASS="expand">
<UL CLASS="navTree">
<LI CLASS="branch">Computer Configuration</LI>
<LI CLASS="branch">Windows Settings</LI>
<LI CLASS="branch">Security Settings</LI>
<LI CLASS="branch">Local Policies</LI>
<LI CLASS="branch">Audit policies</LI>
</UL>
</DIV></LI>
<LI>Right-click <B>Audit account management</B>, and then click <B>Security</B>.</LI>
<LI>Select the <B>Success</B> and <B>Failure</B> check boxes, and then click <B>OK</B>.</LI>
<LI>Using <B>Active Directory Sites and Services</B>, replicate the changed Group Policy object to all domain controllers in the domain or wait for the normal replication cycle.</LI>
</OL>
<P class="note">Notes</P><UL>
<LI>You must be logged on as an administrator or a member of the Aministrators group in order to complete this procedure.</LI>
<LI>To apply the new Group Policy on every domain controller in the domain, run the Secedit tool with the /refreshpolicy machine_policy command line option on each domain controller.</LI>
<LI>For information about forcing replication, see Windows&nbsp;2000 Server Help. </LI>
</UL>
</BODY>
</HTML>