In order to capture Authentication Activity events, the "Audit Logon events" audit policy for all servers and workstations must be enabled.
When Local Policies\Audit Policy is used:
- Enable the ‘Audit Logon events’ audit policy for all servers and workstations. (Set to audit Success and Failure):
- Domain - Group Policy:
- Default Domain Policy\Computer Configuration\Policies\Windows Settings\Security Settings\Local Policies\Audit Policy\Audit logon events
- Default Domain Controller Policy:
- Default Domain Controllers Policy\Computer Configuration\Policies\Windows Settings\Security Settings\Local Policies\Audit Policy\Audit logon events
- Default Domain Controllers Policy\Computer Configuration\Policies\Windows Settings\Security Settings\Advanced Audit Policy Configuration\Audit Policies\Logon/Logoff\Audit Logon
- Workgroup - Local Group Policy:
- Local Computer Policy\Computer Configuration\Policies\Windows Settings\Security Settings\Local Policies\Audit Policy\Audit logon events
- Wait 30-90 minutes for the policy to refresh
When Security Settings\Advanced Audit Policy Configuration is used:
- Enable the ‘Audit Logon’ advanced audit policy for all servers and workstations. (Set to audit Success and Failure):
- Domain - Group Policy:
- Default Domain Policy\Computer Configuration\Policies\Windows Settings\Security Settings\Advanced Audit Policy Configuration\Audit Policies\Logon/Logoff\Audit Logon
- Default Domain Controller Policy:
- Default Domain Controllers Policy\Computer Configuration\Policies\Windows Settings\Security Settings\Local Policies\Audit Policy\Audit logon events
- Default Domain Controllers Policy\Computer Configuration\Policies\Windows Settings\Security Settings\Advanced Audit Policy Configuration\Audit Policies\Logon/Logoff\Audit Logon
- Workgroup - Local Group Policy:
- Local Computer Policy\Computer Configuration\Policies\Windows Settings\Security Settings\Advanced Audit Policy Configuration\System Audit Policies - Local Group Policy Object\Logon/Logoff\Audit Logon
- Wait 30-90 minutes for the policy to refresh