1. | Open Microsoft Management Console (MMC). | ||||||||||||||
2. | On the File menu, click Add/Remove Snap-in, and then click Add. | ||||||||||||||
3. | Click Group Policy Object Editor, and then click Add. | ||||||||||||||
4. | On the Select Group Policy Object page in the Group Policy Wizard, click Browse. | ||||||||||||||
5. | In Browse for a Group Policy Object, select a Group Policy object (GPO) in the appropriate domain, site, or organizational unit--or create a new one, click OK, and then click Finish. | ||||||||||||||
6. | Click Close, and then click OK. | ||||||||||||||
7. | Do one or more of the following:
| ||||||||||||||
8. | Click Advanced, and then click the Auditing tab. | ||||||||||||||
9. | Do one of the following:
| ||||||||||||||
10. | Select the appropriate entry in the Apply onto list. | ||||||||||||||
11. | In the Access box, indicate what actions you want to audit by selecting the appropriate check boxes:
| ||||||||||||||
12. | If you want to prevent files and subfolders in the tree from inheriting these audit entries, select the Apply these auditing entries to objects and/or containers within this container only check box. |
Important
| • | Before setting up auditing for files and folders, you must enable object access auditing by defining auditing policy settings for the object access event category. If you do not enable object access auditing, you will receive an error message when you set up auditing for files and folders, and no files or folders will be audited. For more information about how to enable object access auditing, see "Define or modify auditing policy settings for an event category" in Related Topics. |
Notes
| • | To perform this procedure, you must be a member of the Domain Admins group or the Enterprise Admins group in Active Directory, or you must have been delegated the appropriate authority. As a security best practice, consider using Run as to perform this procedure. For more information, see Default local groups, Default groups, and Using Run as. | ||||
| • | To open Microsoft Management Console, click Start, click Run, type mmc, and then click OK. | ||||
| • | For more information on selecting where to apply auditing entries, see Related Topics. | ||||
| • | You can set up file and folder auditing only on NTFS drives. | ||||
| • | If you see the following:
auditing is inherited from the parent folder. | ||||
| • | After object access auditing is enabled, view the security log in Event Viewer to review the results of your changes. | ||||
| • | Because the security log is limited in size, select the files and folders to be audited carefully. Also, consider the amount of disk space that you want to devote to the security log. The maximum size for the security log is defined in Event Viewer. |
| InitWizard("3b5204b3-8b18-4b14-babd-a81532331af61033"); |