Interactive login event if 528 not appearing in sbs security event log for domain users



Hi,
I have been working on this issue for a couple of days now and have
read through many previous posts, the windows server 2003 security
guide and the Threats and Countermeasures: Security Settings in
Windows Server 2003 and Windows XP guides.

We have a SBS 2003 SP1 server no R2 and the windows security event log
shows event id 528 logon type 2 interactive logon for the
administrator account only. The workstations are all joined to the
domain and I receive a lot of event if 540 which is the network logon
when domain users logon however we never see the event id 528.

I have set the following under Computer Configuration -> Windows
Settings -> Security Settings -> Local Policies -> Audit Policy under
the Small Business Server Auditing Policy GPO.

Account Logon Events (Success & Failure)
Account Management (Success & Failure)
Logon Events (Success & Failure)
Object Access (Failure)
Policy Change (Success & Failure)
Privilege Use (Failure)
Process Tracking (Failure)
System Events (Success & Failure)

I have run a gpudpate /force on the SBS and also checked to ensure
that no other policies are overwriting the GPO. I did this by typing
gpedit.msc going to Local Computer and expanding Computer
Configuration -> Windows Settings -> Security Settings -> Local
Policies -> Audit Policy. All settings match the settings above.

I have rebooted the SBS server and still I can't see users interactive
logon events. I have setup a test server in our lab running SBS 2003
and even with the default settings I don't see the users interactive
logons. Enabled the settings above also makes no difference.

I know I can use the network logon event if 540 however this logs
access to a NTFS file share, printer etc and what we want to establish
is when a user logs onto their computer and when they logout. Could
you please advise if this is by design and I'm chasing my tail here??

Why is only the administrator user account showing in the event 528
interactive logon? We also see event ID 528 generated for the SYSTEM
and BESAdmin (Black Berry User Account) account but not for
interactive logon rather logon type 5 which is service.


Interestingly if I view the linked list of GPO's the Small Business
Server Auditing Policy does not appear, I presume this is because the
policy is applied to the domain controller only not the entire
domain?

The domain controller policy has by default
Account Logon Events (Success)
Logon Events (Success)

Hence regardless it should log the interactive logons???

The default domain policy does not define any settings. Just for
interest sake I set both the Domain Controller and default domain
policy's the same as the auditing policy and still I can't see the
interactive logons.

Any help would be greatly appreciated. Please let me know if you
require any more information.

Kind Regards,
Chiper

.



Relevant Pages

  • RE: Trend, IIS, Permissions, Exhaustion and close to very bad language :-) Heelp!
    ... I understand when you logon on Company web ... Does the IP address point your Windows XP clients or SBS Server? ... Is the IP address of the Windows XP client or server that in your network? ...
    (microsoft.public.windows.server.sbs)
  • Kerberos logon failure - Windows Server 2003 RTM
    ... Domain controller with Windows 2003 RTM. ... Authentication server with Windows Server 2003 RTM (Proxy ... Users logon to the web site from the authentication server and are ... see Help and Support Center at ...
    (microsoft.public.win2000.security)
  • Re: Native Mode possible problems...help!
    ... their password will still be able to logon to an NT 4.0 - but using their ... Windows 2003/2000/NT ... > They NT 4.0 domain controllers will still be able to authenticate users, ... > Why not just upgrade the BDCs to Windows 2000 Server? ...
    (microsoft.public.windows.server.general)
  • Re: WebDAV problem with digest authentication behind firewall
    ... I'm using IIS 6.0 on a windows 2003 enterprise server which is member of a windows 2000 ads. ... is the one from inside the firewall. ... > connection and they both got a logon box. ...
    (microsoft.public.inetserver.iis)
  • Re: Windows 98/ME having problem to log-on Windows 2000 domain
    ... Can you ping the server by both IP address and name? ... are you entering credentials in the logon for Microsoft Networking box ... > i have few windows xp and windows 98/ME as the clients of my domain. ...
    (microsoft.public.win2000.security)