Granular Audit Policies not logging failures or lockout


we migrated our default domain policy server 2003, included legacy auditing options. recently, modified policy use granular audit. followed these steps on default domain policy:

1. set legacy options not configured.

2. enabled "audit: force audit policy subcategory settings"

3. set following audit settings under logon/logoff (and no other advanced audit settings) logon: success , failure, logoff: failure, account lockout: success , failure, special logon: failure

4. when run "auditpol /get /category:*" can see settings applied on both domain controllers

my problem: see successful logons (id 4624) in event viewer: security settings. failures , account lockouts found, accounts *are* being locked out, , logon failures *are* occurring. missing here?

thanks in advance!

thanks, did come across article trying resolve problem, 1 of better ones on subject. think solved part of problem, failed enable audit user account management. when turned on, account lockouts started showing in event viewer.


Windows Server  >  Group Policy



Comments

Popular posts from this blog

DCOM received error "2147746132" from...

ADFS 3.0 Event ID 4625 | An Error occurred During Logon | Status: 0xC000035B

DFSR RPC replication errors 5014 1726 with large files over VPN