Audit Account Logon Events

  • Thread starter Thread starter Raul Lucky
  • Start date Start date
R

Raul Lucky

Greetings,

Our office is a single domain mixed mode (2000/NT) Active Directory network
and we're trying to get successful audits of our user logon failures. The
following policy was changed at the default GPO:

computer configuration/Windows Settings/Security Settings/Local
Policies/Audit Policy/Audit account logon events: Success/Failure.

Even though we have this policy in place, our domain controllers are not
logging the logon events for either successes or failures. We have no
overiding policies in place and no other settings are set in the Audit
Policy section.

Any thoughts? thanks! Please reply to this group.

Raul
 
Actually we got this to work via the Domain Controller Policy Settings.
Apparently this was overriding our Domain Group Policy. Hope this helps.

Raul
 
That is correct. They probably had enabled auditing of "account logon"
events in which case failures would be recorded on the domain controller
that the domain user tried to authenticate to. --- Steve
 
Back
Top