No Interactive Logon Events under 4625
i reviewing windows event found there no event id=4625 , logon type=2 (interactive logon) since anlayse failed logon normal users.
lateron, have enabled audit policy in active directory gpo follow:
- audit account logon events - success/failure
- audit account management - success/failure
- audit directory service access - failure
- audit logon events - success/failure
- audit object access - success/failure
- audit policy change - success/failure
- audit privilege use - failure
- audit system events - success/failure
- audit processing tracking - no auditing
but after few days, still cannot see events, 4625 logon type=3 can found.
did miss steps or wrong?
angus.
hi angus,
logon type 2: interactive. user logged on computer.
used logon @ console of computer. type 2 logon logged when attempt log on @ windows computer’s local keyboard , screen.
if want find type2 event on dc, need perform local logon, example, use domain admin account log onto 1 dc. in scenario, please try enable both account logon , logon/logoff audit policy categories.
please see similar thread below:
https://social.technet.microsoft.com/forums/windowsserver/en-us/11000de9-ca8b-49c4-8517-a78db29c7923/eventid-4624-logon-type-2-missing?forum=winserversecurity
regards,
wendy
logon type 2: interactive. user logged on computer.
used logon @ console of computer. type 2 logon logged when attempt log on @ windows computer’s local keyboard , screen.
if want find type2 event on dc, need perform local logon, example, use domain admin account log onto 1 dc. in scenario, please try enable both account logon , logon/logoff audit policy categories.
please see similar thread below:
https://social.technet.microsoft.com/forums/windowsserver/en-us/11000de9-ca8b-49c4-8517-a78db29c7923/eventid-4624-logon-type-2-missing?forum=winserversecurity
regards,
wendy
please remember mark replies answers if , un-mark them if provide no help. if have feedback technet subscriber support, contact tnmff@microsoft.com.
Windows Server > Security
Comments
Post a Comment