GetAuditedPermissionsFromAcl
[New
- Windows NT]
The GetAuditedPermissionsFromAcl
function returns the audited access rights for a specified trustee. The audited
rights are based on the access-control entries (ACEs) of a specified
access-control list (ACL). The audited access rights indicate the types of
access attempts that cause the system to generate an audit record in the system
event log. The audited rights include those that the ACL
DWORD GetAuditedPermissionsFromAcl(
PACL pacl, |
// ACL to get trustee s audited rights from |
PTRUSTEE pTrustee, |
// trustee to get rights for |
PACCESS_MASK pSuccessfulAuditedRights, |
// receives rights audited for successful access |
PACCESS_MASK pFailedAuditRights |
// receives rights audited for failed access |
); |
|
Parameters
pacl
Pointer to an
ACL from which to get the trustee s audited access rights.
pTrustee
Pointer to a TRUSTEE
pSuccessfulAuditedRights
Pointer to an
ACCESS_MASK
pFailedAuditRights
Pointer to an
ACCESS_MASK variable that receives a set of access rights based on the
access-control entries in the specified ACL. The system generates an audit
record when the trustee fails in an attempt to use any of these rights.
Return Values
If the
function succeeds, the return value is ERROR_SUCCESS.
If the
function fails, the return value is a nonzero error code defined in WINERROR.H.
Remarks
The GetAuditedPermissionsFromAcl
function checks all system-audit ACEs in the ACL to determine the audited
rights for the trustee. For all ACEs that specify audited rights for a group, GetAuditedPermissionsFromAcl
enumerates the members of the group to determine whether the trustee is a
member. The function returns an error if it cannot enumerate the members of a
group.
See Also