How to Track Changes Made to Files in a Shared Folder

Download Lepide File Server Auditor
Or Deploy With Our Virtual Appliance
In This Article

With data volume growing exponentially, protecting digital assets is becoming increasingly more challenging for most organizations.

Unauthorized modification and relocation of data disrupt the normal business functions and can result in damage to reputation, legal penalties and financial losses. Proactive monitoring of changes made to files and folders helps to reduce cases of theft and accidental exposure of sensitive information.

In this article, we will discuss two methods by which you can detect changes made to any file in a shared folder. One is using the native method, and the other is using Lepide File Server Auditor.

Steps to Track Changes Made to Files in a Shared Folder with Native Auditing

Below are the steps to enable auditing and track events in event logs

Step 1: Configuring the policies

  1. Type “GPMC.msc” in the “Command Prompt” or “Run” dialogue box to open “Group Policy Management” console.
  2. Navigate to “Forest” ➔ “Domains” ➔ “”
  3. Right-click default domain policy or customized policy under “Domain Controllers” node

    Note: We recommend you to create a new Group Policy Object (GPO), link it to the domain and then edit.

  4. To access “Group Policy Management Editor”, click “Edit” in the context menu.
  5. Go to “Computer Configuration” ➔ “Policies” ➔ “Windows Settings” ➔ “Security Settings” ➔ “Local policies” ➔ “Audit policy” ➔ “Audit object access” policy
    Figure 1: “Group Policy Management Editor”
  6. Double-click “Audit object access” policy to open “Properties” window.
    Figure 2: Enable audit policy for “Success” and “Failure”
  7. Click “Define these policy settings”.
  8. Select “Success” and “Failure” checkboxes. Click “Apply” and “Ok”.
  9. Navigate to “Advanced Audit Policy Configuration” ➔ “Audit Policies” ➔ “Object access”.
    Figure 3: Advanced security policies
  10. Configure “Audit File System” policy and “Audit Handle Manipulation” policy.
  11. Open their respective “Properties” window and define the settings for both “Success” and “Failure” events.
  12. Click “Apply” and “Ok” after enabling both audit policies.
  13. To apply policy on the domain, execute the following command in “Command Prompt”:
    gpupdate /force

Step 2: Configure auditing on the file/folder you want to track

You have to perform the following steps at the file or folder. If you perform them on a folder, these settings can be selected to be applied to its sub-folders and files.

  1. Open “Windows Explorer” and navigate to file share that you want to audit.
  2. Right-click the file and click “Properties” in the context menu.
  3. Switch to “Security” tab and click “Advanced” button to open “Advanced Security Settings”
  4. Switch to “Auditing” tab which displays already existing auditing entries.
    Figure 4: “Auditing” tab in “Advanced Security settings” window
  5. Click “Add” to create a new auditing entry. The “Auditing Entry” window opens up on the screen.
  6. Now click “Select a Principal” to choose the users whose activities you want to track. For tracking the activities of all the users, enter “Everyone” in “Enter the object name” box.
  7. Click “Ok” after finalizing your selection.
  8. Select “All” option from “Type” drop-down menu.
    Figure 5: Configuring auditing entry
  9. In the Permissions section, click “Show advanced permission” and select the following:
    • Create files/ write data
    • Create folders/ append data
    • Write attributes
    • Write extended attributes
  10. Click “Ok” to close the “Auditing entry” window. It takes you back to “Auditing” tab of “Advanced Security settings” window.
    Figure 6: Auditing entry “Advanced Security settings” window
  11. Click “Apply” and “Ok” and close file “Properties”.

Step 3: Tracking events in the “Event Viewer”

  1. Let us have a look at the steps to track events:
    • Open “Event Viewer”.
    • Expand “Windows Logs” and select “Security”.
    • Click “Filter current log”.
  2. Event ID 4656 is generated whenever an application attempts to access an object (as per the set audit policy) but does not necessarily mean that any permissions were exercised.
    Figure 7: Event ID 4656 with event details
  3. Event ID 4658 determines the duration for which an object was open.
    Figure 8: Event ID 4658 with event details
  4. Event ID 4663 indicates if permissions like read, write, delete or rename have been exercised.
    Figure 9: Event details of accessed permissions


    Figure 10: “Access Request Information” details of the event
  5. The type of permission accessed is indicated by “Accesses” in the event details.
    Table 1: List of Permissions matching to their values in Event Details

How Lepide File Server Auditor Tracks File Changes in Shared Folders

Lepide File Server Auditor (part of Lepide Data Security Platform) empowers you with the ability to detect critical changes in your business enterprise without having to put in any manual effort. Granular reporting and real time alerts are just a few of the features that help you automate otherwise time-consuming tasks.

The following is a screenshot of “All modifications in Shared file and folder” report generated by Lepide’s File Server Auditor.

All Modifications in Shared Files and Folders
Figure 11: All Modifications in Shared File and Folder report

You can see here how easy it is to dive into all changes being made to shared files and folders. Why don’t you download the free trial of Lepide’s File Server auditing solution today and try it out for yourself?

Download Lepide File Server Auditor

Or Deploy With Our Virtual Appliance