PC Review


Reply
Thread Tools Rating: Thread Rating: 4 votes, 5.00 average.

Audit Logon Events vs. Audit Account Logon Events

 
 
HG
Guest
Posts: n/a
 
      23rd Mar 2004
In a recent Windows 2K Svr checklist from Microsoft I noticed that Microsoft
recomends the admin to do a Sucess and Failure in "Audit Account Logon
Events" only.

see http://www.microsoft.com/technet/sec.../w2ksvrcl.mspx

Enable Security Event Auditing>Microsoft recommends enabling only Success
and Failure auditing for the Audit account logon events policy.

What's the difference between "Audit Account Logon Events" vs. "Audit Logon
Events"?

Thanks,

GX


 
Reply With Quote
 
 
 
 
Steven Umbach
Guest
Posts: n/a
 
      24th Mar 2004
All messages from thread
Message 1 in thread
From: Steven L Umbach ((E-Mail Removed))
Subject: Re: Logon vs Acct logon auditing


View this article only
Newsgroups: microsoft.public.win2000.security
Date: 2004-03-18 12:10:51 PST


This a copy of a reply I made a short time back. I think it depends if the
server or the domain controller will be authenticating the users. ---
SteveThere is a subtle, but important to know, difference when it comes to
trying
to track down account lockouts or hack attempts. Account logon events are
used to record when a user logs onto a computer. The event is recorded on
the computer that authenticated the user - the actual computer [local sam]
if logging onto a local machine account or the domain controller that
validated a domain user logging into the domain. An account logon event will
not be recorded on the domain computer where a domain user logs onto the
domain but a logon event could be. Logon events are recorded where a user
uses their credentials such as accessing a domain file server in which case
a type 3 netwok logon would be recorded in the security log of the file
server showing the name and computer used by the domain user. See the links
below for more info including how to interpret the Event ID's. --- Steve
[bored at work]

http://www.microsoft.com/resources/d.../en-us/515.asp
http://tinyurl.com/2zg73 -- shorter in case of wrap.

http://www.microsoft.com/resources/d.../en-us/518.asp
http://tinyurl.com/34osj -- shorter link in case of wrap.


"HG" <(E-Mail Removed)> wrote in message
news:7JY7c.283014$(E-Mail Removed)...
> In a recent Windows 2K Svr checklist from Microsoft I noticed that Microsoft
> recomends the admin to do a Sucess and Failure in "Audit Account Logon
> Events" only.
>
> see http://www.microsoft.com/technet/sec.../w2ksvrcl.mspx
>
> Enable Security Event Auditing>Microsoft recommends enabling only Success
> and Failure auditing for the Audit account logon events policy.
>
> What's the difference between "Audit Account Logon Events" vs. "Audit Logon
> Events"?
>
> Thanks,
>
> GX
>
>



 
Reply With Quote
 
 
 
Reply

Thread Tools
Rate This Thread
Rate This Thread:

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are Off


Similar Threads
Thread Thread Starter Forum Replies Last Post
SecPol Audit Policy: Diff between "Audit account logon events" and "Audit logon events" ? Sebastian Kaist Windows XP Help 2 13th Mar 2009 04:37 PM
SecPol Audit Policy: Diff between "Audit account logon events" and "Audit logon events" ? Sebastian Kaist Windows XP General 0 13th Mar 2009 08:06 AM
Audit Account Logon Events, Client IP address incorrect? =?Utf-8?B?TG9yaQ==?= Microsoft Windows 2000 Active Directory 7 22nd Dec 2004 01:33 AM
Audit account logon events causes security log meltdown :( Trust No OneŽ Microsoft Windows 2000 Active Directory 1 19th Nov 2004 12:33 AM
logon and account logon audit events djc Microsoft Windows 2000 Security 3 30th Sep 2004 09:16 PM


Features
 

Advertising
 

Newsgroups
 


All times are GMT +1. The time now is 05:13 AM.