KB 240101

KB 240101: Privileged Group Membership rules fail in localized environment

Default rules for monitoring changes to privilege groups fail to trigger Alert in non English environments

Issue: Rules are configured based on Group Name vs SID value

Symptoms: Expected Alert for privilege group change does not appear

Cause: SCOM processes event strings as text vs source SID/GUID values stored in security log

Scope: Any environment running non English versions of Windows or implemented best practices for renaming privileged groups

Product/s: Windows Security Auditor 3.0.6500.0

Rules Impacted based on Filter Expressions

  1. Local Admin Group Membership Change rules
  2. Domain Admin, Enterprise Admin and Schema Admin Group Membership Change rules
Resolution

Create new rules using the 'Group Membership Change for X' monitoring template

News & Events

Press Release 08/04/2009: Secure Vantage Releases Security Auditing SP2 for the Audit Collection Services (ACS)


Online Webcasts 06/08/2009: Download the ACS Master Class Series for free real world expert training on the Audit Collection Services.


Read more