• Home
  • Getting started

    • Quick start
    • Requirements
    • Installing FileAudit
    • Configuring your first audit path
    • Displaying the events
    • Setting up an alert
    • Best practices
  • Reference

    • Core concepts
      • Windows audit
      • Cloud audit
      • Permissions and properties snapshots
      • Access types
    • Reporting
    • Alerts
    • Filters
    • Settings
    • Database
      • Architecture
      • Tables and fields
    • Warnings
    • Keyboard shortcuts
  • How to guides

    • Installation
      • Console installation
      • Connect remotely to a FileAudit service
      • Upgrade procedure
    • Configuration
      • Configure a custom script to run when an alert triggers
      • Detect Ransomware
      • Send notifications to Teams or Slack
      • Configure email settings
      • Manage the license
      • Set up FileAudit permissions
      • Advanced
        • Reduce audit noise from Windows search
        • Reduce Security event log volume
        • Register a Microsoft Entra app for OAuth2
        • Register a Google Cloud app for OAuth2
    • Operations
      • Manage Windows audit
      • Manage permissions and properties snapshots
      • Manage Cloud audit
      • Manage alerts
      • Manage scheduled reports
    • Database
      • Set production database
      • Configure SQL Express
      • Migrate to another database
      • Archive database
      • Clean records
  • Support

    • Need assistance?
    • Changelog
    • FAQ
      • Installation
      • License
      • Database
      • Cloud option
      • Troubleshooting

Core concepts

Understand how FileAudit collects file access events, from Windows and cloud auditing to access types and database architecture.


Windows audit

Native Windows auditing mechanisms used by FileAudit

Cloud audit

Cloud audit mechanisms, supported providers, and collection behavior.

Permissions and properties snapshots

What a snapshot captures: object properties, NTFS permissions, statuses, and storage

Access types

Windows and cloud access types detected by FileAudit

Sign up to our newsletter

Stay up to date with the latest updates and announcements.

Products

  • UserLock
  • FileAudit
  • Open a support ticket

Resources

  • Blog
  • Compliance
  • Active Directory Glossary

Company

  • About
  • Partners
  • Careers
  • Resellers

Contact us

Send us a message or call +1-800-492-3951 / +33 5 59 41 42 20

  • Business privacy policy
  • User license contract
  • General conditions
  • Data processing agreement

© IS Decisions