Event ID : 4624
hi, have following advanced audit policies configured our domain, still dont see event logs machine & user logon details. appreciated.
log name: securitysource: microsoft-windows-security-auditing
date: 9/30/2016 10:48:37 pm
event id: 4624
task category: logon
level: information
keywords: audit success
user: n/a
computer: dc
description:
account logged on.
subject:
security id: null sid
account name: -
account domain: -
logon id: 0x0
logon type: 3
impersonation level: delegation
new logon:
security id: s-1-5-21-3803837968-1534464277-3267097699-47311
account name: l-3plhh92$
account domain: corp
logon id: 0x15b72b10b
logon guid: {07261433-bae2-c8ef-34e8-4aa451c95ab9}
process information:
process id: 0x0
process name: -
network information:
workstation name:
source network address: 10.20.111.50
source port: 55026
detailed authentication information:
logon process: kerberos
authentication package: kerberos
transited services: -
package name (ntlm only): -
key length: 0
hi,
check if "force audit policy subcategory settings (windows vista or later) override audit policy category settings" policy setting enabled. enforce 'advanced' auditing categories.
please see below description of setting:
“legacy audit settings can applied windows versions, advanced audit settings can applied windows vista , above, , windows 2008 , above. implementing both legacy , advanced audit policy settings cause unexpected outcomes due conflicts between similar settings in 2 groups of policy settings. enabling audit: force audit policy subcategory settings (windows vista or later) ensure legacy audit settings ignored. in other words, if option checked, legacy audit policies (pre-vista) not applied , must set under advanced audit policy configuration.”
please verify setting in environment.
more article reference:
audit: force audit policy subcategory settings (windows vista or later) override audit policy category settings
https://technet.microsoft.com/en-us/library/dd772710%28v=ws.10%29.aspx?f=255&mspperror=-2147217396
getting effective audit policy in windows 7 , 2008 r2
best regards,
alvin wang
please remember mark replies answers if , unmark them if provide no help.
if have feedback technet subscriber support, contact tnmff@microsoft.com.
Windows Server > Group Policy
Comments
Post a Comment