Smeglor,
I appreciate the help. I have enabled auditing on the folder and set auditing for Domain Users = Change permissions. I can get the eventvwr to show the event below on a file ACL change. The problem is that it doesn't say which user was granted or removed from the ACL. The change was made by the user Administrator, but the change happened to user test3.
Event Type: Success Audit
Event Source: Security
Event Category: Object Access
Event ID: 560
Date: 2/14/2006
Time: 11:43:59 AM
User: ADTEST\administrator
Computer: TEST2K3
Description:
Object Open:
Object Server: Security
Object Type: File
Object Name: C:\acl\test2.txt
Handle ID: 1428
Operation ID: {0,14552467}
Process ID: 3528
Image File Name: C:\WINDOWS\explorer.exe
Primary User Name: administrator
Primary Domain: ADTEST
Primary Logon ID: (0x0,0xD772D6)
Client User Name: administrator
Client Domain: ADTEST
Client Logon ID: (0x0,0xD772D6)
Accesses: READ_CONTROL
WRITE_DAC
WRITE_OWNER
ACCESS_SYS_SEC
Privileges: SeSecurityPrivilege
SeTakeOwnershipPrivilege
Restricted Sid Count: 0
Access Mask: 0x10E0000
For more information, see Help and Support Center at