[Okta Webinar] Learn how to a build a cloud-first strategyRegister Now


who authenticated to a domain controller

Posted on 2009-04-29
Medium Priority
Last Modified: 2012-05-06
I would like to know what users authenticated to a particular domain controller.

From a domain controller how can i generate a list of users that authenticated, or are currently authenticated to that server ?

From the workstation I know i can just type "set" and look at LOGONSERVER.

but i want to see it from the domain controller itself and see all the users that authenticated to this server .

Question by:Ekuskowski
  • 2
  • 2
LVL 20

Accepted Solution

brwwiggins earned 1200 total points
ID: 24263776
have you enabled audit account logon events?

Author Comment

ID: 24264188
Yes I have it enabled, but it still is not showing me a nice clean list of what users logged into the server. I see a lot of logins that are computer names and not usernames. and I  only see it when I actually open up the event.

When i just look at the list of events USER is system for all account logon event 672 in the Security Log.

Unless there is something else i should be searching for.

LVL 20

Assisted Solution

brwwiggins earned 1200 total points
ID: 24264516
I don't think you will ever get a nice clean list of users who authenticated to a server, what time they authenticated, IP address, etc (removing duplicates for multiple resource access). There are no native tools that I know of to do this. You might have to look at 3rd party tool

LVL 18

Assisted Solution

Americom earned 300 total points
ID: 24266545
There is no built-in feature that could allow you to list all logged on users for the domain.
You can try the 3rd party tool :

Author Closing Comment

ID: 31576093
Thanks for your help, I'll continue using event viewer to find the info

Featured Post

Hire Technology Freelancers with Gigs

Work with freelancers specializing in everything from database administration to programming, who have proven themselves as experts in their field. Hire the best, collaborate easily, pay securely, and get projects done right.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Compliance and data security require steps be taken to prevent unauthorized users from copying data.  Here's one method to prevent data theft via USB drives (and writable optical media).
It’s time for spooky stories and consuming way too much sugar, including the many treats we’ve whipped for you in the world of tech. Check it out!
This tutorial will walk an individual through the steps necessary to join and promote the first Windows Server 2012 domain controller into an Active Directory environment running on Windows Server 2008. Determine the location of the FSMO roles by lo…
This tutorial will walk an individual through the process of transferring the five major, necessary Active Directory Roles, commonly referred to as the FSMO roles from a Windows Server 2008 domain controller to a Windows Server 2012 domain controlle…

834 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question