Solved

login auditing

Posted on 2003-10-22
8
141 Views
Last Modified: 2010-04-14
Is it possible too log everytime someone logs into and out of a client in my domain from a domain controller?
0
Comment
Question by:donnatronious
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 3
  • 2
  • 2
  • +1
8 Comments
 
LVL 11

Accepted Solution

by:
adonis1976 earned 125 total points
ID: 9603061
yeah, enable object access auditing.
0
 
LVL 41

Expert Comment

by:graye
ID: 9604059
Let's be clear....

If you want to know when anybody logs into their domain account anywhere in the network, then you turn on auditing at the Domain Controllers for:
    Audit Account Login Events

But, if you want to know when somebody logs into a specific PC (with either or domain or local acount), then you turn on auditing on that PC for:
    Audit Login Events

...or both!
0
 

Author Comment

by:donnatronious
ID: 9604095
this is under the group policy of the domain controller right?
0
Free eBook: Backup on AWS

Everything you need to know about backup and disaster recovery with AWS, for FREE!

 
LVL 17

Expert Comment

by:paulop1975
ID: 9604103
To accomplish this you'll need to open Control Panel -> Administrative Tools -> Local Security Policy and on the left-pane select Local Policies\Audit Policies.
Then on the right-pane you should be able to see "Audit Account Logon Event" (this one you're looing for) and many other.

Good hunting!
;)
0
 
LVL 17

Expert Comment

by:paulop1975
ID: 9604115
For the Server version of Windows it should be similar.
Sorry but I don't remember the correct way to get to Global Policies. Mine is Windows 2000 Professional.
:(

Good luck on the search!

pAul0|PIm3NTA
0
 
LVL 17

Expert Comment

by:paulop1975
ID: 9604120
Thursday, October 23, 2003
4:12 AM
No cigarettes left......... shouldn't I be sleeping??
:S
0
 

Author Comment

by:donnatronious
ID: 9604170
hmm, I thought I put a comment a minute ago but it didn't show up.

My goal which I should have made clear in the original question is too see failures when someone tries too authenticate with an incorrect password.  adonis1976's solution accomplishes this but graye and paulop1975 do not.  I just tested it.

Thanks

0
 
LVL 41

Expert Comment

by:graye
ID: 9605968
Not to belabor the point... but one of the major difference in Audit Login Events and Audit Account Login Events is... "Audit Login Event" will only capture events where the UserID is valid... whereas "Audit Account Login Events" will capture events where the UserID doesn't even exist.

That's why they are almost always used together...  one to discover UserID guessing, and one to discover Password guessing.
0

Featured Post

Comprehensive Backup Solutions for Microsoft

Acronis protects the complete Microsoft technology stack: Windows Server, Windows PC, laptop and Surface data; Microsoft business applications; Microsoft Hyper-V; Azure VMs; Microsoft Windows Server 2016; Microsoft Exchange 2016 and SQL Server 2016.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

Title # Comments Views Activity
Why won't wireshark open my tcpdump file from linux 13 3,361
Migrate DHCP from server 2000 to 2008 1 645
Remote Access to a Windows 2000 Computer 2 520
Terminal 2000 connection RDP 5 142
NTFS file system has been developed by Microsoft that is widely used by Windows NT operating system and its advanced versions. It is the mostly used over FAT file system as it provides superior features like reliability, security, storage, efficienc…
This article describes how to import an Outlook PST file to Office 365 using a third party product to avoid Microsoft's Azure command line tool, saving you time.
Nobody understands Phishing better than an anti-spam company. That’s why we are providing Phishing Awareness Training to our customers. According to a report by Verizon, only 3% of targeted users report malicious emails to management. With compan…
Exchange organizations may use the Journaling Agent of the Transport Service to archive messages going through Exchange. However, if the Transport Service is integrated with some email content management application (such as an antispam), the admini…

752 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question