User Object class attributes related to logon process, lastLogon, lastLogonTimestamp, badPwCount, badPasswordTime are not audited even when enabled via the Change Auditor Client.
The following registry key is required on each Domain Controller Change Auditor Agent. The Agent service will need to be restarted in order for the logon attributes to be monitored:
Location: Registry
NOTE: If you are using a version prior to 6.9.5, the registry path will reference a non-Quest branded path.
Once the regkey has been implemented, the attributes have to be added to the list of monitored attributes as per the following KB:
https://support.quest.com/change-auditor/kb/64270/how-to-add-unmonitored-object-attribute-64270-
Quest does not provide support for problems that arise from improper modification of the
registry. The Windows registry contains information critical to your computer and applications. Make
sure you back up the registry before modifying it. For more information on the Windows Registry
Editor and how to back up and restore it, refer to Microsoft Article ID 256986 “Description of the
Microsoft Windows registry” at Microsoft Support.
© ALL RIGHTS RESERVED. Feedback Terms of Use Privacy Cookie Preference Center