No Interactive Logon Events under 4625


i reviewing windows event found there no event id=4625 , logon type=2 (interactive logon) since anlayse failed logon normal users.

lateron, have enabled audit policy in active directory gpo follow:

  1. audit account logon events - success/failure
  2. audit account management - success/failure
  3. audit directory service access - failure
  4. audit logon events - success/failure
  5. audit object access - success/failure
  6. audit policy change - success/failure
  7. audit privilege use - failure
  8. audit system events - success/failure
  9. audit processing tracking - no auditing

but after few days, still cannot see events, 4625 logon type=3 can found.

did miss steps or wrong?

angus.

hi angus,
logon type 2: interactive. user logged on computer.
used logon @ console of computer. type 2 logon logged when attempt log on @ windows computer’s local keyboard , screen.
if want find type2 event on dc, need perform local logon, example, use domain admin account log onto 1 dc. in scenario, please try enable both account logon , logon/logoff audit policy categories.
please see similar thread below:
https://social.technet.microsoft.com/forums/windowsserver/en-us/11000de9-ca8b-49c4-8517-a78db29c7923/eventid-4624-logon-type-2-missing?forum=winserversecurity
regards,
wendy

please remember mark replies answers if , un-mark them if provide no help. if have feedback technet subscriber support, contact tnmff@microsoft.com.



Windows Server  >  Security



Comments

Popular posts from this blog

Error: 0x80073701 when trying to add Print Services Role in Windows 2012 Standard

difference between wuauclt1.exe and wuauclt.exe

Windows 2016 RDS event 1306 Connection Broker Client failed to redirect the user... Error: NULL