Hey folks - have a gpo applied to my file server
Computer Config/policies/windows settings/security settings/local policies/ audit policy/policy - "Audit Ojbect Access - Success, Failure"
Computer Config/policies/windows settings/security settings/local policies/Advanced Audit configuration/object access/policy/ "Audit File System - Success, Failure"
Go the my folder that I want auditing enabled on - set it up for one user "Test1" - Audit Success and Failure, Set Permissions to Deny on the folder, attempt to access the folder - no events generated for audit failed, only audit success...
Am I missing something? I would like to see events when a user is denied access to a folder.
THanks.