Jump to content

Recommended Posts

  • 2 months later...
Posted

Create a GPO for you DC's with the following configured.

 

Computer Configuration - Policies - Windows Settings - Security Settings - Local Policies/Audit Policy - Audit logon events

 

Select Failure

 

Gpupdate the DC's

 

Failed logon attempts should show up in Event Viewer for each DC. I think the event ID is 4625.

Posted (edited)
Create a GPO for you DC's with the following configured.

 

Computer Configuration - Policies - Windows Settings - Security Settings - Local Policies/Audit Policy - Audit logon events

 

Select Failure

 

Gpupdate the DC's

 

Failed logon attempts should show up in Event Viewer for each DC. I think the event ID is 4625.

 

Thanks, but I just could not get this to work...

 

Most of the Google searching I did returned that exact method, some others suggest using the 'Advanced Audit Policy Configuration' and I tried both ways, but it just wouldn't record failed logon attempts.

 

Now I can't say that 99% of the posts I found are wrong (somehow I guess it is working for them), but it struck me a little strange that a Local Audit Policy (even on a DC) would record events from Domain Computers anyway (maybe only in a sense that the user is logging into the server to use resources/get permissions/GPO etc.), I couldn't see how that would work and then I came across this and it made a lot more sense (the first answer):

 

https://social.technet.microsoft.com/Forums/exchange/en-US/afa27c0a-4dd0-4a00-be1c-048e2fe9ac75/event-id-4625-not-being-recorded-gp-audit-enabled?forum=winserverTS

 

Basically it states: If Kerberos authentication fails between the client and DC, it never gets the point that the log on fails on the server..

 

So I enabled this and although it is a little verbose (logging computers starting up and such), it seems to do the job!

 

Kerberos.jpg

 

EDIT: If anyone knows why the original method wasn't working (or if it is working in your environment), or a better way to do this please shout!

 

I thought most people would have this enabled to warn of brute force attacks...

Edited by Koldov
Posted (edited)
Just a quick thought. Did you reboot the DC's after applying the policy to them? I think the domains functional level must be at least 2008. Edited by mproffitt1983

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...