audit logon failure

From: mf (md_fk_at_web.de)
Date: 04/29/03


Date: Tue, 29 Apr 2003 10:29:22 +0200


Hi,
I want to track account logon failures in a w2k domain. I've set in the
domain policy the 'audit account logon events' and 'audit logon events' on
failure. When a logon to a member server fails, the event is recorded in the
security log on the member server and not on the domain controller. Is it
possible to track all logon failures in the domain on the domain controller?

Thank you,
Manfred



Relevant Pages

  • Re: security auditing
    ... I enabled 'Audit account logon events' and 'Audit logon events' under Computer Configuration-Windows Settings-Security Settings-Local Policies/Audit Policy for a policy that covers about 15 users to test it. ...
    (microsoft.public.windows.group_policy)
  • Re: security auditing
    ... I enabled 'Audit account logon events' and 'Audit logon events' ... Policies/Audit Policy for a policy that covers about 15 users to test it. ... If you want to log all domain logons, go create the "Audit account logon ...
    (microsoft.public.windows.group_policy)
  • RE: find on which computer is connected a user
    ... You may try to enable the policy "Audit Logon Events" and then audit the ... Write events to the event log of a specified server concerning the status ...
    (microsoft.public.windows.server.general)
  • RE: Logon Failures
    ... logon failures from a external address. ... First, please look at the SBS security event log, and let me know the event ... Configure account lockout policy. ...
    (microsoft.public.windows.server.sbs)
  • RE: how can I see when the last time it was when a computer loged on
    ... You can try to enable the policy "Audit logon events" and then we can audit ... Events->Select Success and Failure. ...
    (microsoft.public.windows.server.sbs)