Hey Joe, long time no see :-D

There are a couple bugs that surfaced for us with AA in 2008 R2. You can also 
cause problems with folks playing with combinations of settings using legacy 
GPO setting, AA GPO, local settings and auditpol

I'd have to root around to get at the specifics but one of the fixes for us was 
to clear all the settings on the problem children with 'auditpol /clear',  in 
some cases we had to make a minor change to the GPO and then set it back to 
what we wanted.

This was a couple years ago but your description sounds eerily familiar.

Also keep in mind that the only source of truth is auditpol. Don't believe 
anything else.  Kind of in the vein of "you are not smarter than the KCC" --  
"GUIs lie about auditing, RSoP can lie about auditing"

Or as the inimitable Ned Pyle put it-


All of this boils down to one lesson: you should not trust any of the Group 
Policy reporting tools when it comes to audit settings. There's only one safe 
bet and it's this command:

auditpol.exe /get /category:*
Only auditpol reads the actual 
super-top-secret-eyes-only-licensed-to-kill-shaken-not-stirred registry key 
that stores the current, effective set of auditing policy that LSASS.EXE 
consumes



This is an awesome reference: 
http://blogs.technet.com/b/askds/archive/2011/03/11/getting-the-effective-audit-policy-in-windows-7-and-2008-r2.aspx


Much drier version here-

AuditPol and Local Security Policy results may differ
https://support.microsoft.com/en-us/kb/2573113

HTH

--bob



From: [email protected] [mailto:[email protected]] On 
Behalf Of Heaton, Joseph@Wildlife
Sent: Friday, May 29, 2015 7:18 AM
To: NT System Admin Issues Discussion list
Subject: [NTSysADM] Group Policy issue

I have a GPO, which has been in place for months now, and working fine.  It has 
been applied to a few of my file servers, to set a bunch of things, including 
some Advanced Auditing settings.  A week ago, I applied this GPO to the rest of 
my file servers.  I have a couple of problem children.  Some of the settings 
for this GPO are being applied, but not the Advanced Auditing.  I do have the 
setting in the GPO to Force audit policy subcategory settings to override audit 
policy category settings.  And, that's one of the settings that is being 
applied.  I've run the gpupdate /force tons of times.  I cannot reboot this 
server at this time.  What else can I do to make these settings apply, short of 
creating another GPO with these settings only to see if they'll apply then.

Thanks,

Joe Heaton
Information Technology Operations Branch
Data and Technology Division
CA Department of Fish and Wildlife
1700 9th Street, 3rd Floor
Sacramento, CA  95811
Desk:  (916) 323-1284

Every Californian should conserve water.  Find out how at:
[SaveOurWater_Logo]<https://urldefense.proofpoint.com/v2/url?u=http-3A__saveourwater.com_&d=AwMFAg&c=hLS_V_MyRCwXDjNCFvC1XhVzdhW2dOtrP9xQj43rEYI&r=TA_mjBT8bS0r8rLrnubGjA&m=3CYeOKLHJzGn4TTbD44jpsJwQGMLTE1Spgku1iwjLuM&s=iXviwlDLqUugJqMY0L95xx3o2q72o043nwAxCkmsg3w&e=>
SaveOurWater.com<https://urldefense.proofpoint.com/v2/url?u=http-3A__saveourwater.com_&d=AwMFAg&c=hLS_V_MyRCwXDjNCFvC1XhVzdhW2dOtrP9xQj43rEYI&r=TA_mjBT8bS0r8rLrnubGjA&m=3CYeOKLHJzGn4TTbD44jpsJwQGMLTE1Spgku1iwjLuM&s=iXviwlDLqUugJqMY0L95xx3o2q72o043nwAxCkmsg3w&e=>
 * 
Drought.CA.gov<https://urldefense.proofpoint.com/v2/url?u=http-3A__drought.ca.gov_&d=AwMFAg&c=hLS_V_MyRCwXDjNCFvC1XhVzdhW2dOtrP9xQj43rEYI&r=TA_mjBT8bS0r8rLrnubGjA&m=3CYeOKLHJzGn4TTbD44jpsJwQGMLTE1Spgku1iwjLuM&s=9P0OFVqysYvqy2xO7N-XFDmHkRFJlnAp_Z2wD-9Bc00&e=>



PG&E is committed to protecting our customers' privacy. 
To learn more, please visit http://www.pge.com/about/company/privacy/customer/

Reply via email to