El envío de formularios en el sitio de soporte no está disponible temporalmente para programar el mantenimiento. Si necesita asistencia inmediata, comuníquese con el soporte técnico. Disculpe las molestias ocasionadas.
ODM Dirsync - SIDHistory Error: "Write: The operation requires that destination domain auditing be enabled I have verified Auditing has been enabled in the target environment" (4325147)
ODM Dirsync - SIDHistory Error: "Write: The operation requires that destination domain auditing be enabled I have verified Auditing has been enabled in the target environment"
Descripción
We receive the following error when syncing SIDHistory:
Error: Write: The operation requires that destination domain auditing be enabled I have verified Auditing has been enabled in the target environment.
Auditing is configured as per the documentation (success and failure) for source and target environments.
Causa
A GPO is enabled that can be overriding the DC policies, or a configuration step was missed.
Resolución
Confirm the domain policy is not overriding the domain controller policy for auditing:
Enable Auditing and Advanced Auditing following the sections below for both the Target & Source Domains:
Audit Policy
Log on as an administrator to any domain controller in the domain.
Click Start, point to All Programs, point to Administrative Tools, and then click Group Policy Management.
Navigate to the following node: Forest | Domains | Domain Name | Domain Controllers | Default Domain Controllers Policy
Right-click Default Domain Controllers Policy and click Edit.
In Group Policy Management Editor, in the console tree, navigate to the following node: Computer Configuration | Policies | Windows Settings | Security Settings | Local Policies | Audit Policy
In the details pane, right-click Audit account management, and then click Properties.
Click Define these policy settings, and then click Success and Failure.
Click Apply, and then click OK.
In the details pane, right-click Audit directory service access and then click Properties.
Click Define these policy settings and then click Success.
Click Apply, and then click OK.
Note: If the changes need to be immediately reflected on the domain controller, open an elevated command prompt and type gpupdate /force.
Advanced Audit Policy
In the Domain Group Policy Management Editor, in the console tree, navigate to the following node: Computer Configuration | Policies | Windows Settings | Security Settings | Advanced Audit Policy Configuration | Audit Policies | Account Management
In the details pane, right click on Audit Application Group Management subcategory and then click Properties.
Click Configure the following audit events and then slick Success and failure.
Click Apply, and then click OK.
Repeat above steps for the following Subcategory Audit Events.
Audit Computer Account Management
Audit Distribution Group Management
Audit User Account Management
Audit Other Account Management Events
Audit Security Group Management
Note: If the changes need to be immediately reflected on the domain controller, open an elevated command prompt and type gpupdate /force.
Your Request will be reviewed by our technical reviewer team and, if approved, will be added as a Topic in our Knowledgebase.
Bienvenido al portal de soporte
Puede encontrar ayuda de soporte en línea para el *producto* Quest en un sitio de soporte afiliado. Haga clic en Continuar para ser dirigido al contenido de soporte y a la asistencia adecuados para el *producto*.