Hey Joe, long time no see :-D There are a couple bugs that surfaced for us with AA in 2008 R2. You can also cause problems with folks playing with combinations of settings using legacy GPO setting, AA GPO, local settings and auditpol
I'd have to root around to get at the specifics but one of the fixes for us was to clear all the settings on the problem children with 'auditpol /clear', in some cases we had to make a minor change to the GPO and then set it back to what we wanted. This was a couple years ago but your description sounds eerily familiar. Also keep in mind that the only source of truth is auditpol. Don't believe anything else. Kind of in the vein of "you are not smarter than the KCC" -- "GUIs lie about auditing, RSoP can lie about auditing" Or as the inimitable Ned Pyle put it- All of this boils down to one lesson: you should not trust any of the Group Policy reporting tools when it comes to audit settings. There's only one safe bet and it's this command: auditpol.exe /get /category:* Only auditpol reads the actual super-top-secret-eyes-only-licensed-to-kill-shaken-not-stirred registry key that stores the current, effective set of auditing policy that LSASS.EXE consumes This is an awesome reference: http://blogs.technet.com/b/askds/archive/2011/03/11/getting-the-effective-audit-policy-in-windows-7-and-2008-r2.aspx Much drier version here- AuditPol and Local Security Policy results may differ https://support.microsoft.com/en-us/kb/2573113 HTH --bob From: [email protected] [mailto:[email protected]] On Behalf Of Heaton, Joseph@Wildlife Sent: Friday, May 29, 2015 7:18 AM To: NT System Admin Issues Discussion list Subject: [NTSysADM] Group Policy issue I have a GPO, which has been in place for months now, and working fine. It has been applied to a few of my file servers, to set a bunch of things, including some Advanced Auditing settings. A week ago, I applied this GPO to the rest of my file servers. I have a couple of problem children. Some of the settings for this GPO are being applied, but not the Advanced Auditing. I do have the setting in the GPO to Force audit policy subcategory settings to override audit policy category settings. And, that's one of the settings that is being applied. I've run the gpupdate /force tons of times. I cannot reboot this server at this time. What else can I do to make these settings apply, short of creating another GPO with these settings only to see if they'll apply then. Thanks, Joe Heaton Information Technology Operations Branch Data and Technology Division CA Department of Fish and Wildlife 1700 9th Street, 3rd Floor Sacramento, CA 95811 Desk: (916) 323-1284 Every Californian should conserve water. Find out how at: [SaveOurWater_Logo]<https://urldefense.proofpoint.com/v2/url?u=http-3A__saveourwater.com_&d=AwMFAg&c=hLS_V_MyRCwXDjNCFvC1XhVzdhW2dOtrP9xQj43rEYI&r=TA_mjBT8bS0r8rLrnubGjA&m=3CYeOKLHJzGn4TTbD44jpsJwQGMLTE1Spgku1iwjLuM&s=iXviwlDLqUugJqMY0L95xx3o2q72o043nwAxCkmsg3w&e=> SaveOurWater.com<https://urldefense.proofpoint.com/v2/url?u=http-3A__saveourwater.com_&d=AwMFAg&c=hLS_V_MyRCwXDjNCFvC1XhVzdhW2dOtrP9xQj43rEYI&r=TA_mjBT8bS0r8rLrnubGjA&m=3CYeOKLHJzGn4TTbD44jpsJwQGMLTE1Spgku1iwjLuM&s=iXviwlDLqUugJqMY0L95xx3o2q72o043nwAxCkmsg3w&e=> * Drought.CA.gov<https://urldefense.proofpoint.com/v2/url?u=http-3A__drought.ca.gov_&d=AwMFAg&c=hLS_V_MyRCwXDjNCFvC1XhVzdhW2dOtrP9xQj43rEYI&r=TA_mjBT8bS0r8rLrnubGjA&m=3CYeOKLHJzGn4TTbD44jpsJwQGMLTE1Spgku1iwjLuM&s=9P0OFVqysYvqy2xO7N-XFDmHkRFJlnAp_Z2wD-9Bc00&e=> PG&E is committed to protecting our customers' privacy. To learn more, please visit http://www.pge.com/about/company/privacy/customer/
