H
help
At the moment, on a Windows 2000 with SP4 server that is a Domain
Controller, if I have the following policies set with the DC Security
Policy:
Audit Account Logon Events: None
Audit Logon Events: Success+Failures
then I get mulitple events logged for each instance of log-on and log-off
To be precise, for logons, I get Event IDs:
528 Successful Logon
515 A trusted logon process has registered with the Local Security
Authority. This logon process will be trusted to submit logon requests.
540 Successful Network Logon: TWICE
For Logoffs
538 Successful Logoffs: multiple entries
Controller, if I have the following policies set with the DC Security
Policy:
Audit Account Logon Events: None
Audit Logon Events: Success+Failures
then I get mulitple events logged for each instance of log-on and log-off
To be precise, for logons, I get Event IDs:
528 Successful Logon
515 A trusted logon process has registered with the Local Security
Authority. This logon process will be trusted to submit logon requests.
540 Successful Network Logon: TWICE
For Logoffs
538 Successful Logoffs: multiple entries