Auditing Workstation logons from DC

Auditing Workstation logons from DC

Secure Home | Search | About
 Microsoft Applications Security    Post an article   get this group's latest topics as an RSS feed add this group's latest topics to your My MSN content add this group's latest topics to your My Yahoo content add this group's latest topics to your Google content
Subject Author Date
Auditing Workstation logons from DC Andy1974 01-24-2006
Posted by =?Utf-8?B?QW5keTE5NzQ=?= on January 24, 2006, 1:16 pm
If you were  Registered and logged in, you could reply and use other advanced thread options
I am trying to see workstation interactive logins in the Windows 2003 DC
event viewer but am not seeing the events. I am seeing Remoteinteractive as
well as interactive directly into the Domain Controller itself. However
workstation computers that are a member of the domain are not registering
event 528 or 539 type 2's in the event viewer. I have Domain Security
Settings for Audit account logon to Success and Audit logon events to
success. I have Domain Controller Settings to audit account logon to Success
and Failure and Audit Logon to Success and Failure. I am running Windows
2003 Small Business Server.

Posted by Patrick Dickey on January 24, 2006, 5:27 pm
If you were  Registered and logged in, you could reply and use other advanced thread options
Andy1974 wrote:
> I am trying to see workstation interactive logins in the Windows 2003 DC
> event viewer but am not seeing the events. I am seeing Remoteinteractive as
> well as interactive directly into the Domain Controller itself. However
> workstation computers that are a member of the domain are not registering
> event 528 or 539 type 2's in the event viewer. I have Domain Security
> Settings for Audit account logon to Success and Audit logon events to
> success. I have Domain Controller Settings to audit account logon to Success
> and Failure and Audit Logon to Success and Failure. I am running Windows
> 2003 Small Business Server.

Hi Andy,
Realizing that this is a security issue, I would suggest posting (or
crossposting) this to the Windows Server newsgroups as well.
specifically the
news://msnews.microsoft.com/microsoft.public.windows.server.sbs (Small
Business Server newsgroups) or the
news://msnews.microsoft.com/microsoft.public.windows.server.security
(Windows Server 2003 security) newsgroup or the
news://msnews.microsoft.com/microsoft.public.windows.group_policy (Group
Policy newsgroup). They'll be able to help you, even though you're on
Small Business Server.

HTH
--
http://www.pats-computer-solutions.com
Smile.. someone out there cares deeply for you.

Posted by Roger Abell [MVP] on January 24, 2006, 7:52 pm
If you were  Registered and logged in, you could reply and use other advanced thread options
You may want to think about looking directly at the security logs of
the client systems, using such as EventCombMT
http://search.microsoft.com/results.aspx?mkt=en-US&setlang=en-US&q=eventcombmt

Alternatively if you are adventurous look into LogParser
http://www.logparser.com/

--
Roger

>I am trying to see workstation interactive logins in the Windows 2003 DC
> event viewer but am not seeing the events. I am seeing Remoteinteractive
> as
> well as interactive directly into the Domain Controller itself. However
> workstation computers that are a member of the domain are not registering
> event 528 or 539 type 2's in the event viewer. I have Domain Security
> Settings for Audit account logon to Success and Audit logon events to
> success. I have Domain Controller Settings to audit account logon to
> Success
> and Failure and Audit Logon to Success and Failure. I am running Windows
> 2003 Small Business Server.



Posted by =?Utf-8?B?TWlrZQ==?= on March 8, 2006, 7:07 pm
If you were  Registered and logged in, you could reply and use other advanced thread options
I am also experiencing the same problem. The only 528 events logged in the
DC's are interactive, terminal services and unlock events for the domain
controllers only. There are no 528 events being logged for the workstations.

Through GPO, I've enabled "audit account logon events" and "audit logon
events" at the "default domain controller" policy and the "default domain"
policy.

I see 540's, 538's, and Kerberos events but no 528's for the workstations in
the domain.

I've verified this on two separate forests. One is production, one is pure
testing but both are Server 2003 w/SP1 and up-to-date patches. All of my
clients are XP SP2, up-to-date as well.

The production domain was a legacy upgrade from our initial Windows 2000 AD
deployment 6 years ago. The upgrade process was done using the docs so the
pre-req preps were done.

The test domain is a fresh 2k3 install, no legacy.

Both domains do exactly the same thing. Am I missing something?

The reason I am interested in 528 Type: 2 is because we'd like to compile
interactive login stats over time. Is there a better way of doing this?


Mike
PC Network Specialist
School of Architecture/Telecom
New Jersey Institute of Technology


"Andy1974" wrote:

> I am trying to see workstation interactive logins in the Windows 2003 DC
> event viewer but am not seeing the events. I am seeing Remoteinteractive as
> well as interactive directly into the Domain Controller itself. However
> workstation computers that are a member of the domain are not registering
> event 528 or 539 type 2's in the event viewer. I have Domain Security
> Settings for Audit account logon to Success and Audit logon events to
> success. I have Domain Controller Settings to audit account logon to Success
> and Failure and Audit Logon to Success and Failure. I am running Windows
> 2003 Small Business Server.

Similar ThreadsPosted
SmartCard logons to domain November 30, 2005, 9:17 am
Verify AD User CAC Logons June 22, 2006, 4:40 pm
remote access logons in Event Viewer July 28, 2005, 12:06 pm
Workstation Security September 29, 2007, 1:42 pm
NT4 Workstation accessing 2000 DC November 9, 2005, 8:11 am
source workstation question June 28, 2006, 3:09 am
Security (Keep the admin out of the workstation) December 1, 2008, 11:09 pm
NT4 workstation in 2003 server domain July 12, 2005, 1:43 pm
Isolating 1 Workstation from the rest of the network January 17, 2006, 10:08 am
Record of when last login occurred on an XP workstation May 19, 2006, 9:34 am

The site map in XML format XML site map

Contact Us | Privacy Policy