How can a Windows file server identify who deleted, changed, or accessed a shared file?
Reliable file auditing requires advanced audit policy, folder SACLs, adequate log capacity, central retention, and analysis of event 4663 together with SIDs, ownership, and access paths.
Reliable file auditing requires advanced audit policy, folder SACLs, adequate log capacity, central retention, and analysis of event 4663 together with SIDs, ownership, and access paths. For this case, first verify advanced audit policy and target-directory SACL, then use events 4663/4660 and related audit records to decide whether remediation is needed.
Define the failure boundary first
For this file access and permissions case, establish the failure boundary with advanced audit policy and SACL, then continue to events 4663/4660 and related audit records. Capture the current state, incident time and one known-good comparison before changing production configuration.
Work through the dependency chain
| Check | Why it matters | Recommended action |
|---|---|---|
| 01 · advanced audit policy | Verify advanced audit policy on the affected path using logs, counters or state information rather than relying only on the configured rule. | Record the current value, evidence source and timestamp for advanced audit policy. If adjustment is required, change one condition only and retain the original setting for rollback. |
| 02 · target-directory SACL | Verify target-directory SACL on the affected path using logs, counters or state information rather than relying only on the configured rule. | Check target-directory SACL read-only and save the result. If it differs from the baseline, correlate it with the incident time and recent changes before remediation. |
| 03 · events 4663/4660 and related audit records | Verify events 4663/4660 and related audit records on the affected path using logs, counters or state information rather than relying only on the configured rule. | Compare events 4663/4660 and related audit records with a known-good peer, the log timeline and the real application path; confirm whether it is causal before changing production. |
| 04 · log capacity and retention | Review the current state, related logs and recent changes for log capacity and retention, then align them with the incident timeline before deciding whether a change is required. | Record the current value, evidence source and timestamp for log capacity and retention. If adjustment is required, change one condition only and retain the original setting for rollback. |
| 05 · user SID and share-access path | Review the current state, related logs and recent changes for user SID and share-access path, then align them with the incident timeline before deciding whether a change is required. | Check user SID and share-access path read-only and save the result. If it differs from the baseline, correlate it with the incident time and recent changes before remediation. |
| 06 · centralized logging and time synchronization | Review the current state, related logs and recent changes for centralized logging and time synchronization, then align them with the incident timeline before deciding whether a change is required. | Compare centralized logging and time synchronization with a known-good peer, the log timeline and the real application path; confirm whether it is causal before changing production. |
Change only after the evidence is clear
- Start with read-only evidence. Check advanced audit policy and target-directory SACL before changing configuration.
- If the first checks are normal, continue with events 4663/4660 and related audit records and log capacity and retention, keeping evidence tied to the incident time.
- Change configuration only when the evidence explains the symptom. For user SID and share-access path, preserve the original value and define the rollback trigger before adjustment.
- Validate centralized logging and time synchronization in a controlled scope before expanding to production users or traffic.
Validation and rollback
- Validate the complete user or application workflow; do not stop at the single status of advanced audit policy.
- Recheck user SID and share-access path and centralized logging and time synchronization after the change and confirm that no new bypass, permission expansion or secondary error has appeared.
- Archive evidence from advanced audit policy through centralized logging and time synchronization, together with before/after configuration, business validation and the rollback point.
Common wrong turns
- Changing advanced audit policy and SACL at the same time, which makes the original cause impossible to prove.
- Treating a normal result for events 4663/4660 and related audit records as proof that log capacity and retention and the rest of the business path are healthy.
- Leaving a temporary exception related to user SID and share-access path or centralized logging and time synchronization in production without an owner, expiry time and rollback note.
Related questions
Where should I start with “How can a Windows file server identify who deleted, changed, or accessed a shared file?”?
Start with advanced audit policy and target-directory SACL; they establish the first useful troubleshooting boundary without changing production state.
What should be checked after the first layer looks normal?
Continue with events 4663/4660 and related audit records and log capacity and retention, then correlate the result with the incident time and the actual user or application path.
What should be retained after the change?
Keep evidence for user SID and share-access path and centralized logging and time synchronization, plus the original configuration, validation result, observation notes and rollback point.
