Where are DC security log entries coming from

I wanted to design auditing from scratch and went into Default Domain group policy and set all items in  Computer Configuration/Windows Settings/Security Settings/Local Policies/Audit Policy to No auditing but yet the entries keep coming in.  Running AD 2008

svenswensonAsked:
Who is Participating?
 
svenswensonConnect With a Mentor Author Commented:
Opened Microsoft support call and they stated you cannot stop all audting for your own protection
0
 
Mike KlineCommented:
Check the default domain controller policy too.

Thanks

Mike
0
 
svenswensonAuthor Commented:
Yep default domain controller policy is no auditing
0
Making Bulk Changes to Active Directory

Watch this video to see how easy it is to make mass changes to Active Directory from an external text file without using complicated scripts.

 
Mike KlineCommented:
What types of entries are you seeing?
0
 
svenswensonAuthor Commented:
Event ids 4624,4634,4769,and 4776
0
 
Mike KlineCommented:
Are you seeing those for every login to the domain?
0
 
svenswensonAuthor Commented:
Yes, including many anonymous and workstation logins
0
 
svenswensonAuthor Commented:
Microsoft does not allowed all auduting o be diabled
0
Question has a verified solution.

Are you are experiencing a similar issue? Get a personalized answer when you ask a related question.

Have a better answer? Share it in a comment.

All Courses

From novice to tech pro — start learning today.