Audit in/out logins only by domain
Hello,
first sorry for my bad english. I want to audit only when a user log in and log out in the domain, and if it's posible from which machine. I want do it only by domain no by each server. That's possible? How can I do it?
Thank you very much.
March 13th, 2012 5:16am
You can configure the audit logon events in group policy (Computer Configuration\Policies\Windows Settings\Security Settings\Local Policies\Audit Policy)
read this articles
http://blogs.technet.com/b/askds/archive/2011/03/11/getting-the-effective-audit-policy-in-windows-7-and-2008-r2.aspx
http://technet.microsoft.com/en-us/library/dd408940(v=ws.10).aspx
Free Windows Admin Tool Kit Click here and download it now
March 13th, 2012 5:45am
Hi,
Thanks for your post.
In Windows Server 2008 and vista, there are nine basic audit policies under
Computer Configuration\Policies\Windows Settings\Security Settings\Local Polices\Audit Policy. In Windows Server 2008 R2 and Windows 7, we can audit more specific aspects of client behavior on the computer or network by creating an advanced audit
policy under Computer Configuration\Policies\Windows Settings\Security Settings\Advanced Audit Policy Configuration\System Audit Policies.
On other way, we can also use the audipol.exe command-line utility to configure various auditing settings. Then, copy the settings to startup script in domain policy. For detailed steps, please reference the below KB article.
How to use Group Policy to configure detailed security auditing settings
http://support.microsoft.com/kb/921469
Auditpol
http://technet.microsoft.com/en-us/library/cc731451(v=ws.10).aspx
Best Regards,
Aiden
Aiden Cao
TechNet Community Support
March 15th, 2012 10:42pm