Pricing  Get Quote
 
 
 

How to audit logon events?

Audit logon events is a security audit policy setting that determines whether each event of a user logging on to or logging off from a device needs to be audited. You can define this policy setting to audit successes, and failures of logon events or not audit this event type at all. For domain account activity, account logon events are generated on domain controllers and for local account activity, account logon events are generated on local devices.

This security policy setting can be configured at Computer Configuration -> Windows Settings -> Security Settings -> Local Policies -> Audit Policy.

About ADAudit Plus:

ADAudit Plus is a real time change auditing software that helps keep your Active Directory, Azure AD, Windows file servers, NetApp filers, EMC file systems, Synology file systems, Windows member servers, and workstations secure and compliant. With ADAudit Plus, you can get visibility into:

There are more than 200 event-specific reports, and you can configure instant email alerts. You can also export the reports to XLS, HTML, PDF and CSV formats to assist in interpretation and forensics.

Audit and monitor Windows security policy settings in real time with ADAudit Plus.

Download Now