2008 audit
i need to get user log on and log off details of users using Active directory service.
i can get the log on using TGT. and i know that AD does not keep record of log off event.
but i can see a Kerberos SGT occur when log off.
why is that?
Is it ok to use it as log off event
June 27th, 2012 5:48am