To audit drive mappings you will need to do the following steps:
1. Turn on Object Access Auditing via Group Policy on the system(s) in question
You will need to perform the following steps on each system that you want to track the drive mappings
2. Open the registry and drill down to HKEY_CURRENT_USER\Network
3. Right click on Network and choose Permissions (if you click on the plus sign you will see each of your mapped drive listed)
4. Click on the Advanced button
5. Click on the Auditing tab then click on the Add button
6. In the Select User or Group box type in Everyone
7. This will open the Auditing dialog box
8. Select the settings that you want to audit for; stay away from the Full Control option and Read Control. I recommend the following settings: Create Subkey, Create Link and Delete.
沒有留言:
張貼留言