As a system administrator, you've probably already heard users complaining about mysteriously disappearing files.
In order to solve one of the most common computer mysteries, and incidentally, to find and pin down the culprit so that justice can be done, we need to activate file auditing on our file-sharing server.
Activating this audit will enable us to retrieve a wealth of information on any modifications or accesses that may be made to a given folder or file (read access, deletion, ACL modification and so on…)
To enable file auditing we need to create a new GPO.
We now need to connect to our Windows File Server to enable File Auditing on a folder.
Let's assume we want to enable auditing on the \\SRV-DATA\01-Admin share.
C:\> gpresult /r /z
The audit result will be available in security log of the event log.
Contact :