All, We have run into some issues in the past where NTFS permissions were changed on a file server after our office rolled it out and turned it over to the local IT technicians. We have enabled auditing on a test server and found that security event id 560 is logged anytime someone attempts to change permissions on this folder. The problem is, event 560 is used for multiple object access ID's. Is there anyway to determine when file permissions are changed other than by auditing and monitoring event 560?
thanks
