Audit Account Log Events

Archived from groups: microsoft.public.win2000.security (More info?)

Hi.

Need help with a GPO. I'm trying to deploy a Domain Based Policy that tracks
account log on events, but i'm having problems.

I created an OU and "drop" the PCs i need to catch the POlicy to that OU. I
created the Policy and linked to the OU, but nothing happen. Any ideas?

PS: if i setup the policy on each PCs, i mean, locally, it works, but i need
to deploy the policies at Domain level.

Thanks in advanced,
3 answers Last reply
More about audit account events
  1. Archived from groups: microsoft.public.win2000.security (More info?)

    For domain users, you need to enable auditing of account logon events in
    Domain Controller Security Policy and you will see the account logon events
    for domain users recorded in the security log of the domain controller that
    authenticated the user. --- Steve


    "Joe" <Joe@discussions.microsoft.com> wrote in message
    news:7667F80D-C1A7-483C-89CC-C18070D76B5C@microsoft.com...
    > Hi.
    >
    > Need help with a GPO. I'm trying to deploy a Domain Based Policy that
    > tracks
    > account log on events, but i'm having problems.
    >
    > I created an OU and "drop" the PCs i need to catch the POlicy to that OU.
    > I
    > created the Policy and linked to the OU, but nothing happen. Any ideas?
    >
    > PS: if i setup the policy on each PCs, i mean, locally, it works, but i
    > need
    > to deploy the policies at Domain level.
    >
    > Thanks in advanced,
  2. Archived from groups: microsoft.public.win2000.security (More info?)

    Hi Steven.

    I tought the security log events are recorded on each event viewer's member
    server (not Domain Controller). That's what i'm expecting to.

    "Steven L Umbach" wrote:

    > For domain users, you need to enable auditing of account logon events in
    > Domain Controller Security Policy and you will see the account logon events
    > for domain users recorded in the security log of the domain controller that
    > authenticated the user. --- Steve
    >
    >
    > "Joe" <Joe@discussions.microsoft.com> wrote in message
    > news:7667F80D-C1A7-483C-89CC-C18070D76B5C@microsoft.com...
    > > Hi.
    > >
    > > Need help with a GPO. I'm trying to deploy a Domain Based Policy that
    > > tracks
    > > account log on events, but i'm having problems.
    > >
    > > I created an OU and "drop" the PCs i need to catch the POlicy to that OU.
    > > I
    > > created the Policy and linked to the OU, but nothing happen. Any ideas?
    > >
    > > PS: if i setup the policy on each PCs, i mean, locally, it works, but i
    > > need
    > > to deploy the policies at Domain level.
    > >
    > > Thanks in advanced,
    >
    >
    >
  3. Archived from groups: microsoft.public.win2000.security (More info?)

    Not for account logons. Account logons are recorded on the computer that
    authenticates the user and for domain account that would be domain
    controllers. You could however enable auditing of logon events on domain
    computers which will show domain users accessing a domain computer by
    recording a logon event in the security log of the computer accessed. . --
    Steve


    "Joe" <Joe@discussions.microsoft.com> wrote in message
    news:E7631F75-E7B6-4FCD-8FE1-4E677190E7FB@microsoft.com...
    > Hi Steven.
    >
    > I tought the security log events are recorded on each event viewer's
    > member
    > server (not Domain Controller). That's what i'm expecting to.
    >
    > "Steven L Umbach" wrote:
    >
    >> For domain users, you need to enable auditing of account logon events in
    >> Domain Controller Security Policy and you will see the account logon
    >> events
    >> for domain users recorded in the security log of the domain controller
    >> that
    >> authenticated the user. --- Steve
    >>
    >>
    >> "Joe" <Joe@discussions.microsoft.com> wrote in message
    >> news:7667F80D-C1A7-483C-89CC-C18070D76B5C@microsoft.com...
    >> > Hi.
    >> >
    >> > Need help with a GPO. I'm trying to deploy a Domain Based Policy that
    >> > tracks
    >> > account log on events, but i'm having problems.
    >> >
    >> > I created an OU and "drop" the PCs i need to catch the POlicy to that
    >> > OU.
    >> > I
    >> > created the Policy and linked to the OU, but nothing happen. Any ideas?
    >> >
    >> > PS: if i setup the policy on each PCs, i mean, locally, it works, but i
    >> > need
    >> > to deploy the policies at Domain level.
    >> >
    >> > Thanks in advanced,
    >>
    >>
    >>
Ask a new question

Read More

Policy Domain Events Windows