Use expression based audit policies
Use expression based audit policies for user/group based auditing
April 23, 2017
Q. What are expression-based audit policies?
A. Expression based audit policies enables auditing to be configured based on security principals defined via group policy that applied to all files and folders instead of having to set policies on the file system or registry directly.
Open a group policy object
Navigate to Computer Configuration - Policies - Windows Settings - Security Settings - Advanced Audit Policy Configuration - Audit Policies - Global Object Access Auditing
Select either File system or Registry
Check the "Define this policy setting" and click Configure
Click Add and select a security principal, the type of audit and then the events that should be audited
Click OK
Once the policies are applied the events that meet the policy will be audited.
About the Author
You May Also Like