Hi i want tools or audit policy that can help me to track all changes made to windows server registry (include who done the change - what is the old value -what is new value -change type {delete -create - modify)
Your support is highly appreciated
Hi i want tools or audit policy that can help me to track all changes made to windows server registry (include who done the change - what is the old value -what is new value -change type {delete -create - modify)
Your support is highly appreciated
Windows Security Log Event ID 4657 will tell you when someone edits a registry key, so you can look for that in your Event Viewer. The only caveat to this is that you have to turn on auditing first. See this to turn on auditing for both domain and workgroup environments.
This is also a link from Microsoft supporting the method from techtarget.com.