Granular Audit Policies not logging failures or lockout
we migrated our default domain policy server 2003, included legacy auditing options. recently, modified policy use granular audit. followed these steps on default domain policy:
1. set legacy options not configured.
2. enabled "audit: force audit policy subcategory settings"
3. set following audit settings under logon/logoff (and no other advanced audit settings) logon: success , failure, logoff: failure, account lockout: success , failure, special logon: failure
4. when run "auditpol /get /category:*" can see settings applied on both domain controllers
my problem: see successful logons (id 4624) in event viewer: security settings. failures , account lockouts found, accounts *are* being locked out, , logon failures *are* occurring. missing here?
thanks in advance!
Windows Server > Group Policy
Comments
Post a Comment