Darksat IT Security Forums
January 12, 2026, 10:13:42 pm
Welcome, Guest. Please login or register.

Login with username, password and session length
News: Darksat IT Security Forum
From Firewall Support, AntiVirus Questions, Spyware problems, Linux and Windows Security, Black Hat SEO right down to Website Design and Multimedia
 
  Home Help Search Gallery Links Staff List Login Register  

Can We find out Domain Controller Policy has been Applied?

Pages: [1]
  Print  
Author Topic: Can We find out Domain Controller Policy has been Applied?  (Read 2648 times)
Darksat
Administrator
Master
*******
Posts: 3303



View Profile WWW
« on: June 18, 2008, 09:30:27 am »

use GPMC (Group Policy Management Console)
http://www.petri.co.il/download_gpmc.htm

To monitor policy changes you can change your GPO (Default Domain Controller Policy) to audit policy changes. The setting is here:

MACHINE Config
Windows Settings\Security Settings\Local Policies\Audit Policy      Audit policy change

I recommend auditing success and failure.
The event will appear in various DCs security logs according to which ever one the GP edit tool attaches to (I think it defaults to the infrastructure master)

The users will get an SCECLI event in their local application event log which tells you of success or failure of a policy application


Also you might look at RsOP and Tripwire
Report Spam   Logged

Pages: [1]
  Print  
 
Jump to:  

Powered by EzPortal
eXTReMe Tracker
Security Forum
Bookmark this site! | Upgrade This Forum
SMF For Free - Create your own Forum


Powered by SMF | SMF © 2016, Simple Machines
Privacy Policy
Page created in 0.031 seconds with 13 queries.