No Interactive Logon Events under 4625


i reviewing windows event found there no event id=4625 , logon type=2 (interactive logon) since anlayse failed logon normal users.

lateron, have enabled audit policy in active directory gpo follow:

  1. audit account logon events - success/failure
  2. audit account management - success/failure
  3. audit directory service access - failure
  4. audit logon events - success/failure
  5. audit object access - success/failure
  6. audit policy change - success/failure
  7. audit privilege use - failure
  8. audit system events - success/failure
  9. audit processing tracking - no auditing

but after few days, still cannot see events, 4625 logon type=3 can found.

did miss steps or wrong?

angus.

hi angus,
logon type 2: interactive. user logged on computer.
used logon @ console of computer. type 2 logon logged when attempt log on @ windows computer’s local keyboard , screen.
if want find type2 event on dc, need perform local logon, example, use domain admin account log onto 1 dc. in scenario, please try enable both account logon , logon/logoff audit policy categories.
please see similar thread below:
https://social.technet.microsoft.com/forums/windowsserver/en-us/11000de9-ca8b-49c4-8517-a78db29c7923/eventid-4624-logon-type-2-missing?forum=winserversecurity
regards,
wendy

please remember mark replies answers if , un-mark them if provide no help. if have feedback technet subscriber support, contact tnmff@microsoft.com.



Windows Server  >  Security



Comments

Popular posts from this blog

Error: 0x80073701 when trying to add Print Services Role in Windows 2012 Standard

Disconnecting from a Windows Server 2012 R2 file sharing session on a Windows 7,8,10 machine

Event ID 64,77,1008 Certificates Events Windows Server 2008, 2008R2