Direct Inward Dialing: +1 408 916 9892
Once ADAudit Plus has been installed, it automatically configures audit policies required for Active Directory auditing.
To enable automatic configuration: Log in to the ADAudit Plus web console -->Domain Settings --> Audit Policy: Configure.
Changes in Windows file integrity can be identified by following the below mentioned steps:
ADAudit Plus enables IT administrators to have a comprehensive picture of all the activities that happen within an organization's network. The real-time monitoring and out-of-the-box reports generated by ADAudit Plus makes it easier to track changes made to critical files and folders, and detect inappropriate access and prevent mishaps.
With native AD auditing, here is how you can monitor file integrity:
Launch Server Manager in your Windows Server instance.
Under Manage, select Group Policy Management and launch the Group Policy Management console.
Navigate to Forest ➔ Domain ➔ Your domain ➔ Domain Controllers.
Create a new GPO and link it to the domain containing the file to be monitored, or edit any existing GPO that is linked to the domain to open the Group Policy Management Editor.
Navigate to Computer Configuration ➔ Windows Settings ➔ Security Settings ➔ Advanced Audit Policy Configuration ➔ Object Access.
The Object Access lists all of its sub-policies in the right panel, as shown in the figure below.
Select the Audit File Systems and enable audit for Success events.
Click Applyand OK to close Properties window.
Open Windows Explorer, navigate to the file or folder you want to monitor.
Right-click the folder and select Properties.
In the Properties window, go to the Security tab and select Advanced. After that select Auditing tab and click Add.
Click on Select a principal.This will bring up a Select User, Computer or Group Window.
Type Everyone in the textbox and verify it with Check Names.
The principal field in the Auditing Entry window now shows Everyone.
In theType drop-down select All to audit for both success and failure events.
In the Applies to drop-down choose This folder, subfolder and files. This allows the auditing of all the subfolders and files within the folder.
Select Full Controlin the Permissions section.
Click Apply,then OK, and close the console.
In Event Viewer window, go to Windows Logs ➔ Security logs.
Click on Filter current logunder Actionin the right panel.
Search for Event ID 4656 that identifies file integrity changes.
You can double-click on the event to view Event Properties.
These steps need to be repeated for all the files and folders to audit file integrity. Manually checking every event is time-consuming, inefficient and practically impossible for large organizations.
Native auditing becoming a little too much?
Simplify file integrity auditing and reporting with ADAudit Plus.
Get Your Free Trial Fully functional 30-day trial