Jump to content

Tracing a Logon ID: for a policy change


Recommended Posts

Posted

Hello,

I'm trying to track down who made a change to the default domain audit

policy, and the event includes this info (data altered) in an event ID 612:

 

Changed By:

User Name: DOMAINCONTROLLER$

Domain Name: OURDOMAIN

Logon ID: (0x1,0x4B7)

 

How do I decipher that Logon ID? I've checked a couple of different DC's

(including the PDC Emulator) but it still doesn't show me the proper user ID.

  • Replies 2
  • Created
  • Last Reply
Guest S. Pidgorny
Posted

You decifer that like this: you have a computer named DOMAINCONTROLLER,

from which the change was replicated to where this was logged.

 

--

Svyatoslav Pidgorny, MCSE, RHCE

-= F1 is the key =-

 

http://sl.mvps.org http://msmvps.com/blogs/sp

 

BillK wrote:<span style="color:blue">

> Hello,

> I'm trying to track down who made a change to the default domain audit

> policy, and the event includes this info (data altered) in an event ID 612:

>

> Changed By:

> User Name: DOMAINCONTROLLER$

> Domain Name: OURDOMAIN

> Logon ID: (0x1,0x4B7)

>

> How do I decipher that Logon ID? I've checked a couple of different DC's

> (including the PDC Emulator) but it still doesn't show me the proper user ID.

>

> </span>

Posted

To amend my original post and to respond to S. Pidgorny, here's the answer I

have from further research (though I'm not thrilled with it and welcome

additional info):

 

The event will always show "Domaincontroller$" as the user name because

from the perspective of Windows server, the system makes the change to GPO's,

not the administrator.

The only way to effectively track down a policy change is to enable file

level auditing and audit for writes against the GPO files themselves under

SYSVOL (becuase this will reflect the admin's user ID when modifying the

object). This webinar shows how to go about it in conjunction with a

vendor's log aggregation product:

http://www.prismmicrosys.com/Training/Trac...icyChanges.html

 

This is really disappointing but I'd love to know if it's simpler in

Windows 2008...

 

- Bill

"BillK" wrote:

<span style="color:blue">

> Hello,

> I'm trying to track down who made a change to the default domain audit

> policy, and the event includes this info (data altered) in an event ID 612:

>

> Changed By:

> User Name: DOMAINCONTROLLER$

> Domain Name: OURDOMAIN

> Logon ID: (0x1,0x4B7)

>

> How do I decipher that Logon ID? I've checked a couple of different DC's

> (including the PDC Emulator) but it still doesn't show me the proper user ID.

>

> </span>

Join the conversation

You can post now and register later. If you have an account, sign in now to post with your account.

Guest
Reply to this topic...

×   Pasted as rich text.   Paste as plain text instead

  Only 75 emoji are allowed.

×   Your link has been automatically embedded.   Display as a link instead

×   Your previous content has been restored.   Clear editor

×   You cannot paste images directly. Upload or insert images from URL.


×
×
  • Create New...