auditing question

From: djc (noone_at_nowhere.com)
Date: 05/17/04


Date: Mon, 17 May 2004 10:12:59 -0400

Win 2000 Server sp4 (single site domain) - the audit policies I'm refering
were created in 'domain security policy'.

I have 'account logon' enabled to audit failed account logon attempts. I
tested and it worked. However I also enabled the auditing of 'logon' events
(failed) and it itsn't doing what I expect. If I'm remembering correctly
'account logon' is only the actuall domain login process (eg.. after
ctrl+alt+del.. logon screen) and 'logon' is after the account logon. For
example 'logon' would be connecting to a network share or printer.

1) please correct me if I'm wrong on diff between 'logon' and 'account
logon'.
2) When testing by trying to connect to a share I don't have access to (I
recieve 'access denied' error message) nothing is logged in the event viewer
security log? Whats wrong? Do 'logon' events have to be used in conjunction
with 'object access' events?

any help is appreciated. Thanks.



Relevant Pages

  • Re: Audit: Account Logon Vs. Logon Events
    ... "Account Logon" events correspond to credential validation- when a machine ... > Determines whether to audit each instance of a user logging on, ... > unchecking Success and Failure. ...
    (microsoft.public.win2000.security)
  • Re: auditing logons - someone please clear this #@#$! up.
    ... Probably the best short explanation I have heard is that "account logon" ... domain controller that authenticates the user while "logon" events will be ... security log of the domain computer [assuming auditing of "logon" events is ...
    (microsoft.public.win2000.security)
  • Re: auditing logons - someone please clear this #@#$! up.
    ... > Probably the best short explanation I have heard is that "account logon" ... > "logon" events are created where the account is used. ... > domain controller that authenticates the user while "logon" events will be ... > security log of a domain controller that is usually showing not that the ...
    (microsoft.public.win2000.security)
  • Re: event IDs 681, 529 and error code 3221225572
    ... context of the log) and say "That's a hacker". ... When examining logon failures, go to the workstation that is generating ... > the "Account Logon" ... > I receive dozens logon failure audits per day about logon ...
    (microsoft.public.win2000.security)
  • Re: logon/logoff logging...
    ... These settings were enabled specifically to audit domain user account ... The settings also audit computer account and system account logon ... authenticating Domain Controller. ...
    (microsoft.public.windows.server.active_directory)