G
Guest
I have Windows 2000 Pro with SP3 Workstation that is a part of a Domain.
In that Workstation's "Local Security Policy" - "Security Settings" - "Local Policies", I enabled the following:
"Audit account logon events" to Success
"Audit logon events" to Success, Failure
"Audit system events" to Success.
When I LOCKED the workstation, the Security Event Viewer shows Event ID 538 indicating that my UserName has logoff.
However, if I actually LOGOFF OR RESTART that Workstation, the Security Event Viewer does NOT show Event ID 538.
The above issue also occurs even if I use Active Directory's Group Policy to set the "Local Policies".
Please help.
Sincerely,
Ibnu.
In that Workstation's "Local Security Policy" - "Security Settings" - "Local Policies", I enabled the following:
"Audit account logon events" to Success
"Audit logon events" to Success, Failure
"Audit system events" to Success.
When I LOCKED the workstation, the Security Event Viewer shows Event ID 538 indicating that my UserName has logoff.
However, if I actually LOGOFF OR RESTART that Workstation, the Security Event Viewer does NOT show Event ID 538.
The above issue also occurs even if I use Active Directory's Group Policy to set the "Local Policies".
Please help.
Sincerely,
Ibnu.