Security Basics mailing list archives

Windows 2000 Audit Question


From: Michael Ungar <m_ungar () yahoo com>
Date: Sat, 2 Aug 2003 22:42:13 -0700 (PDT)

Windows 2000 has 2 Audit Policy Settings;

1 - Audit account logon events &
2 - Audit logon events

I'm not totally clear on the difference. I know the
first one is used as a central repository for auditing
logons (e.g., domain account logons to multiple
servers can get recorded to the central domain
controller log file), but not sure as to second. Does
the second setting record successes / failures of
local authentication attempts ?

Thanks...Mike Ungar

---------------------------------------------------------------------------
----------------------------------------------------------------------------


Current thread: