Tracing Account Logon Location
hi there
i'm having issue logon events accounts, functioning "service accounts" not registered\recorded in security event log on domain controllers.
when viewing lastlogon attribute on user object can see time when account logged onto specific dc. when go security event log , @ logs same time period nothing recorded. i've gone far enable debug logging on dc in attempt find source. surprise though lastlogon attribute object on dc got updated, not picked in netlogon.log file.
has experienced this? there cases lastlogon attribute gets updated not recorded in logs?
thanks
turns out lastlogon attribute gets updated event id 4768 - related kerberos ticket granting ticket requests.
so in order determine source of account usage 1 needs monitor event id 4768 along 4624.
Windows Server > Directory Services
Comments
Post a Comment