62 lines
2.7 KiB
HTML
62 lines
2.7 KiB
HTML
<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.0//EN"
|
|
"http://www.w3.org/TR/REC-html40/strict.dtd">
|
|
<HTML DIR="LTR">
|
|
<HEAD>
|
|
<TITLE>Enable auditing on a Windows 2000 domain</TITLE>
|
|
|
|
<LINK REL="stylesheet" MEDIA="screen" TYPE="text/css" HREF="coUA.css">
|
|
<LINK REL="stylesheet" MEDIA="print" TYPE="text/css" HREF="coUAprint.css">
|
|
|
|
<SCRIPT LANGUAGE="JScript" SRC="shared.js"></SCRIPT>
|
|
|
|
<META HTTP-EQUIV="Content-Type" CONTENT="text-html;charset=Windows-1252">
|
|
<META HTTP-EQUIV="PICS-Label" CONTENT='(PICS-1.1 "<http://www.rsac.org/ratingsv01.html>" l comment "RSACi North America Server" by "inet@microsoft.com <mailto:inet@microsoft.com>" r (n 0 s 0 v 0 l 0))'>
|
|
|
|
|
|
<META NAME="MS.LOCALE" CONTENT="EN-US">
|
|
<META NAME="MS-IT-LOC" Content="Active Directory Migration Tool">
|
|
<META NAME="MS-HAID" CONTENT="a_ADMTSetW2KAuditing">
|
|
</HEAD>
|
|
<BODY>
|
|
|
|
|
|
|
|
<P CLASS="procLabel">To enable auditing on a Windows 2000 domain</P>
|
|
|
|
<OL>
|
|
<LI>On a computer with administrative access to the Windows 2000 domain, click <B>Start</B>, point to <B>Programs</B>, point to <B>Administrative Tools</B>, and then click <B>Active Directory Users and Computers</B>.</LI>
|
|
<LI>In the console tree, right-click <B>Domain Controllers</B>, and then click <B>Properties</B>.</LI>
|
|
<LI>On the <B>Group Policy</B> tab , click <B>Default Domain Controller Policy</B>, and then click <B>Edit</B>.</LI>
|
|
<LI>In the <B>Group Policy</B> console tree, double-click <B>Audit policies</B>.
|
|
<P CLASS="navTree"><A ID="expand" HREF="#" CLASS="where">Where?</A></P>
|
|
|
|
<DIV CLASS="expand">
|
|
<UL CLASS="navTree">
|
|
<LI CLASS="branch">Computer Configuration</LI>
|
|
|
|
<LI CLASS="branch">Windows Settings</LI>
|
|
|
|
<LI CLASS="branch">Security Settings</LI>
|
|
|
|
<LI CLASS="branch">Local Policies</LI>
|
|
|
|
<LI CLASS="branch">Audit policies</LI>
|
|
</UL>
|
|
</DIV></LI>
|
|
<LI>Right-click <B>Audit account management</B>, and then click <B>Security</B>.</LI>
|
|
<LI>Select the <B>Success</B> and <B>Failure</B> check boxes, and then click <B>OK</B>.</LI>
|
|
<LI>Using <B>Active Directory Sites and Services</B>, replicate the changed Group Policy object to all domain controllers in the domain or wait for the normal replication cycle.</LI>
|
|
</OL>
|
|
<P class="note">Notes</P><UL>
|
|
<LI>You must be logged on as an administrator or a member of the Aministrators group in order to complete this procedure.</LI>
|
|
|
|
<LI>To apply the new Group Policy on every domain controller in the domain, run the Secedit tool with the /refreshpolicy machine_policy command line option on each domain controller.</LI>
|
|
|
|
<LI>For information about forcing replication, see Windows 2000 Server Help. </LI>
|
|
|
|
</UL>
|
|
</BODY>
|
|
</HTML>
|
|
|
|
|