Re: File that manages login details

From: Steven L Umbach (n9rou_at_nospam-comcast.net)
Date: 01/25/05

  • Next message: Roger Abell: "Re: Global.msads.net Login Screen"
    Date: Mon, 24 Jan 2005 23:11:33 -0600
    
    

    OK. Just enable auditing of logon events and system events assuming your
    computer is XP Pro. You can use Computer Management/Event Viewer - security
    to see these events once you enable them in Local Security Policy
    [secpol.msc in the run box] and go to security settings/local policies/audit
    policy. The link below explains more. --- Steve

    http://support.microsoft.com/default.aspx?scid=KB;en-us;q248260 --- same
    for XP Pro.

    "Jojy K Kuriakose" <JojyKKuriakose@discussions.microsoft.com> wrote in
    message news:3AD14519-165D-4DDF-9373-CF370EF31354@microsoft.com...
    > Thanx for the Help
    >
    > Let me explain my problem in detail.
    > Well I have a laptop with Xp installed.
    > I have created a number of users so that my friends and family may login
    > to
    > the system.
    > So I would like to know if there is a file that shows me (if not all but
    > some of them) information such as the users who have logged in the time of
    > login in and logging out time , if the user has selected shut down ,
    > hibernate , restart etc!!
    > As you can see it would be helpful in a number of ways.
    >
    > Jojy
    >
    > "Steven L Umbach" wrote:
    >
    >> There is no such file but if you enable auditing of account logon events
    >> for
    >> Domain Controller Security Policy and logon events for Domain Security
    >> Policy or Local Security Policy most of that information is available in
    >> the
    >> security logs in Event Viewer. You can use the free Event Comb to scan
    >> the
    >> security logs of multiple computer or buy a third party program that can
    >> centralize certain security log events. LanGuard has such a program and I
    >> believe they offer a thirty day trial. --- Steve
    >>
    >> http://www.gfi.com/lanselm/
    >>
    >> "Jojy K Kuriakose" <Jojy K Kuriakose@discussions.microsoft.com> wrote in
    >> message news:C083C302-E9B3-4036-9F72-6231177281D2@microsoft.com...
    >> > Is there a file that manages the login details.
    >> > Details of the users who has loged in, how long they logged in, time
    >> > they
    >> > loged out,
    >> > if they chose shut down or hybernate ... etc
    >> > is there a file that the administrator can view o see which all users
    >> > have
    >> > loged in
    >> >
    >>
    >>
    >>


  • Next message: Roger Abell: "Re: Global.msads.net Login Screen"

    Relevant Pages

    • Re: How do I find out when user XXX logged in+out on last Tuesday? Event log entry possible?
      ... You can do that through the local security policy. ... In the right hand pane, right click on Audit logon events. ...
      (microsoft.public.windowsxp.help_and_support)
    • Re: Windows XP User logs
      ... You can do that through the local security policy. ... In the right hand pane, right click on Audit logon events. ...
      (microsoft.public.windowsxp.security_admin)
    • Re: Authentication Auditing
      ... You have to enable auditing of "logon events" for the domain computers which ... could be done in Domain Security Policy. ... The reason "audit logon events" does not ... work for domain computers is because the account logon event is only ...
      (microsoft.public.win2000.security)
    • Re: Terminal Services Auditing not working
      ... I followed your steps for auditting logon events to the T and it ... I make to the local security policy can't be overidden. ... Then using the Terminal Services Configuration tool I've right clicked ...
      (Focus-Microsoft)
    • Re: DMZ NT4 TO Internal 2000 AD One-Way Trust via Firewall
      ... leverage an effectivity security policy to ensure that password complexities ... > currently a mess of local and domain users, no security policy, etc. ... DMZ, not publicly accessible) that aren't going away within the stated ... to non-DC web servers in the DMZ on 80 and 443 - none of which are directed ...
      (microsoft.public.windows.server.active_directory)