I am running multiple Windows server 2008 R2. And the clients are running either Windows XP SP3 or Windows 7 SP1.
I have a folder to hold all of the users home folders. D:\Users\Staff In this folder are all of the users folders. Each server has a similar folder structure.
During the day folder User1 will change its permissions and lock out the administrators. After fixing the issue, it will happen again. It may be on User1 again or it may be different users. And it can be multiple users. The users do not have the ability to change permissions.
On the local server I turned on "Audit object access". When the policies refresh, the settings are turned off. So I have been unsuccessful in finding the cause. I have checked the Group Policies and nothing is turning off Audit object access. It seems as if the change in the permissions on the folders happens at the same time as Audit object access gets cleared.
If I create a GPO with Audit object access turned on, the settings are locked and turned off but the winning GPO is the GPO turned on.
We started filtering out the desktop.ini file because it was making the folders all look like My Documents.
We started noticing this issue over the summer. I do not know how long it has been happening.
I have been trying to catch the offending process with Audit object access, AccessEnum, EventViewer, and ProcMon.
Any help is appreciated.
Charles