mkennedy.dublin Posted May 23, 2007 Posted May 23, 2007 Hello AllI cannot see another forum for this, so I hope it is OK to put it here. I have a problem with local group policies and IIS6. The issue is that on machine reboot, the local group policies, in particular the audit policies are reset to a default. I am running this on windows 2003. Before the reboot I set the policies to: Audit Account Logon Events - Success, FailureAudit account management - Success, FailureAudit directory service access - FailureAudit logon events - Success, FailureAudit object access - Success, FailureAudit policy change - Success, FailureAudit privilege Use - FailureAudit process tracking - No auditingAudit system events - Success, FailureAfter the reboot, the policies are reset to:Audit Account Logon Events - Success, FailureAudit account management - Success, FailureAudit directory service access - No auditingAudit logon events - Success, FailureAudit object access - No auditingAudit policy change - Success, FailureAudit privilege Use - No AuditingAudit process tracking - Success, FailureAudit system events - Success, FailureHave you come across this before and / or do you know any way around this? Thanks in advance for all help received. Regards,Mary
cluberti Posted May 24, 2007 Posted May 24, 2007 Audit directory service access - FailureAudit object access - Success, FailureAudit privilege Use - FailureAudit process tracking - No auditingAfter the reboot, the policies are reset to:Audit directory service access - No auditingAudit object access - No auditingAudit privilege Use - No AuditingAudit process tracking - Success, FailureAs to the "Audit directory service access" policy, this can only be run against an AD domain controller. Therefore, when the box is booted, since this is likely a standalone server, the policy is reset to no auditing. As to the other settings being reset, is this server a member of a domain with GPO policies that could be setting these on reboot? Also, can you reproduce this issue perhaps on another box or VM built from a retail or OEM CD that is not a part of a domain?
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now