Re: windows 2000 lock workstation auditing

From: Eric Fitzgerald [MSFT] (ericf@online.microsoft.com)
Date: 03/13/03


From: "Eric Fitzgerald [MSFT]" <ericf@online.microsoft.com>
Date: Thu, 13 Mar 2003 13:32:06 -0800


No events are logged when a workstation is locked. We will be changing that
in the Longhorn release. You see a logon and logoff event at unlock, as we
use a call to LogonUser() to validate the user's password at unlock, and
then destroy the resultant, unneeded logon session.

Eric

-- 
Eric Fitzgerald
Program Manager, Windows Auditing and Intrusion Detection
Microsoft Corporation
This posting is provided "AS IS" with no warranties, and confers no rights.
"J Bowers" <jbowers@nospam.analytika.com> wrote in message
news:0d7901c2e7f5$afff40a0$7d02280a@phx.gbl...
> I've been searching for information about a problem I'm
> having.  I need to see the time when a workstation is
> locked.  Auditing is enabled, but I only get both the 528
> and 538 events when the machine is unlocked.  Nothing is
> logged when it is locked.
>
> I've found one reference that matches my problem, but with
> no reason given for the problem, status of it, or fixes
> available.
>
> Thanks for any help,
> Jeremy


Relevant Pages

  • Re: bad logon attempts against the Unlock dialog box dont count
    ... Are you trying to unlock the machine with a different user than who has ... Can you please send precise steps to reproduce the problem? ... > a server or workstation using Ctrl+Alt+Delete, bad logon attempts against ...
    (microsoft.public.win2000.security)
  • Unlocking Workstations
    ... running a pure Windows 2000 Server/Workstation environment with active ... workstation locks after 15 minutes of inactivity. ... or an administrator can unlock the workstation. ... networked workstations is a Domain Administrator. ...
    (microsoft.public.win2000.security)
  • Re: Unlocking Workstations
    ... I'm> running a pure Windows 2000 Server/Workstation environment with active ... I have a policy enabled that makes it so that the> workstation locks after 15 minutes of inactivity. ... only the user> or an administrator can unlock the workstation. ... I had thought about> creating an account called "unlock" that users could use to unlock other> workstations, but there is no way I can have a generic domain administrator> account on my system. ...
    (microsoft.public.win2000.security)
  • Re: Email on user login/unlock
    ... I want to have a script fire off an email when a user logs in to one ... or when they unlock their session. ... Your best bet to detect when someone logs in is to use a domain-wide logon ... or program would be able to detect when the user unlocked the workstation. ...
    (microsoft.public.windows.server.scripting)
  • User cant log on (weird)
    ... One user keeps experiencing the following--he locks his workstation ... and then can't unlock it. ... code 0x18 which indicates logon failed due to wrong username or password. ... But user has correct username in logon box and is typing password correctly. ...
    (microsoft.public.windows.server.active_directory)