Tracing Account Logon Location


hi there

i'm having issue logon events accounts, functioning "service accounts" not registered\recorded in security event log on domain controllers.

when viewing lastlogon attribute on user object can see time when account logged onto specific dc. when go security event log , @ logs same time period nothing recorded. i've gone far enable debug logging on dc in attempt find source. surprise though lastlogon attribute object on dc got updated, not picked in netlogon.log file.

has experienced this? there cases lastlogon attribute gets updated not recorded in logs?

thanks

turns out lastlogon attribute gets updated event id 4768 - related kerberos ticket granting ticket requests. 

so in order determine source of account usage 1 needs monitor event id 4768 along 4624.



Windows Server  >  Directory Services



Comments

Popular posts from this blog

2008 Windows Deployment Server Properties Error

Can no longer user MS Update - Files required to use Microsoft Update are no longer registered

How do a find data in one file, search for it in another file and if not found, write a custom message to another file