Use expression based audit policies

Use expression based audit policies

Q. What are expression-based audit policies?

A. Expression based audit policies enables auditing to be configured based on security principals defined via group policy that applied to all files and folders instead of having to set policies on the file system or registry directly.

  1. Open a group policy object
  2. Navigate to Computer Configuration - Policies - Windows Settings - Security Settings - Advanced Audit Policy Configuration - Audit Policies - Global Object Access Auditing
  3. Select either File system or Registry
  4. Check the "Define this policy setting" and click Configure
  5. Click Add and select a security principal, the type of audit and then the events that should be audited
  6. Click OK

Once the policies are applied the events that meet the policy will be audited.

Hide comments

Comments

  • Allowed HTML tags: <em> <strong> <blockquote> <br> <p>

Plain text

  • No HTML tags allowed.
  • Web page addresses and e-mail addresses turn into links automatically.
  • Lines and paragraphs break automatically.
Publish