All,

We have run into some issues in the past where NTFS permissions were
changed on a file server after our office rolled it out and turned it
over to the local IT technicians. We have enabled auditing on a test
server and found that security event id 560 is logged anytime someone
attempts to change permissions on this folder. The problem is, event
560 is used for multiple object access ID's. Is there anyway to
determine when file permissions are changed other than by auditing and
monitoring event 560?

thanks

Reply via email to