|
|
microsoft.public.security Affichage de l'article : RE: Audit Privilege Use - Windows 2003 Security Guide
Date :
Le 04 avril 2008
From :
Miles Li [MSFT]
Sujet :
RE: Audit Privilege Use - Windows 2003 Security Guide
Hello Gareth,
Thank you for your post.
To answer your question, no, it is not correct. From my test, when using
the non-admin user account without necessary privileges, a failure audit
will be logged in Security event log.
Here is a sample Failure Audit event when a user without system shutdown
privilege tries to restart the computer by running 'shutdown -r' in the
commend prompt.
Failure Audit
Event ID: 578
Privileged object operation:
Object Server: Win32 Registry/SystemShutdown module
Object Handle: 0
Process ID: 352
Primary User Name: Computer_name
Primary Domain: Domain_name
Primary Logon ID: (0x0,0x3E7)
Client User Name: User_name
Client Domain: Domain_name
Client Logon ID: (0x0,0x4F0BA)
Privileges: SeShutdownPrivilege
Please confirm whether the related computer has successfully applied the
audit group policy and then check whether similar Failure Audit logs are
recorded in event log.
Hope it helps. Thanks.
Sincerely,
Miles Li
Microsoft Online Partner Support
Microsoft Global Technical Support Center
Get Secure! - www.microsoft.com/security
=====================================================
When responding to posts, please "Reply to Group" via your newsreader so
that others may learn and benefit from your issue.
=====================================================
This posting is provided "AS IS" with no warranties, and confers no rights.
Posez vos questions, réponses et remarques sur
les forums de AuthSecu
|
|