A neat trick to help you diagnose troublesome security problems. Modify your the audit settings for process tracking, so that successes and failures are logged in your Security log.
If you define this policy setting, you can specify whether to audit successes, audit failures, or not audit the event type at all. Success audits generate an audit entry when the process being tracked succeeds. Failure audits generate an audit entry when the process being tracked fails.
These audits are now tracked in the Security log in the Event Viewer. Here's an example of a "Detailed Tracking" event.
Some additional details can be found on TechNet.
Pretty easy to configure, and very useful when you're trying to figure out why applications are not running appropriately and you think it might be related to security issues.
Remember Me
a@href@title, b
Page rendered at Tuesday, January 06, 2009 12:41:20 PM (Central Standard Time, UTC-06:00)
Disclaimer The opinions expressed herein are my own personal opinions and do not represent my employer's view in anyway.