Re: logon/logoff logging...
- From: "MartinX" <a@xxx>
- Date: Tue, 29 Nov 2005 18:13:00 -0500
>From my personal notes regarding this subject -
The two GPO settings below have been enabled for success and failure
auditing:
Default Domain Controllers Policy\Computer Configuration\Windows
Settings\Security Settings\Local Policies\Audit Policy\Audit account logon
events
Default Domain Controllers Policy\Computer Configuration\Windows
Settings\Security Settings\Local Policies\Audit Policy\Audit logon events
These settings were enabled specifically to audit domain user account
logons. The settings also audit computer account and system account logon
activities. The entries are logged to the Security Event Log of the
authenticating Domain Controller.
>From the Microsoft Windows Server 2003 Web site:
"If both account logon and logon audit policy categories are enabled, logons
that use a domain account generate a logon or logoff event on the
workstation or server, and they generate an account logon event on the
domain controller. Additionally, interactive logons to a member server or
workstation that use a domain account generate a logon event on the domain
controller as the logon scripts and policies are retrieved when a user logs
on."
Martin
MCSA: M
"Dave McDougall" <dave.mcdougall@xxxxxxxxxxxx> wrote in message
news:enKgqzR9FHA.1416@xxxxxxxxxxxxxxxxxxxxxxx
> Hey,
>
> How can I log my domain logons and logoffs? Is it on the domain controller
> in AD or is it something I should eb able to see using event viewer?
>
> I want to manage the security of my domain better by monitoring who is
> logging in and out each day.
>
> Thanks
> Dave
>
.
- References:
- logon/logoff logging...
- From: Dave McDougall
- logon/logoff logging...
- Prev by Date: Re: Utility to count AD objects...
- Next by Date: Using extended rights to control application behaviour
- Previous by thread: Re: logon/logoff logging...
- Next by thread: Re: logon/logoff logging...
- Index(es):
Relevant Pages
|