|
Thanks... that will help me get started. Auditing is already turned on on our servers. However, this doesn't catch all situations... for instance:
1. Almost all our users are local admins on their own workstations. 2. If a user walked away from his workstation, another user could create a local account there and place it in the administrators group in only a few seconds. 3. Then the other user could log on to that workstation from his own workstation and browse at his leisure without having to log on to the domain.
Right now, the only thing we could do is find the local account that was created (ostensibly by the owner of the workstation). But with local auditing, we could pin down the other activity as well.
We don't use AD. I'll look into domain policies as a way to enable/disable this at the workstation level.
We have avoided workstation policies like the plague. Microsoft has turned this into a horror story with conflicting policy settings and methods among their different products. As we have worked with Microsoft on policy questions, they admitted that organizations wanting to really use policies to best advantage (read: make them really work in complex situations) have people dedicated full time to those issues. Yuck.
Maybe with Microsoft's new attitude toward security, they will actually work with each other within the company to get some of these issues ironed out and consistent.
Thanks for the help!
New Mexico Mark
|