Jump to content

Recommended Posts

Posted

Im not sure if this has ever been asked on here but is there a way to monitor failed logons on specific machines. For example, if Joe Bloggs is trying to guess Fred Smith's logon details on computer 1 and this is causing Fred to be locked out of the network during his logon session while working on computer 2?

 

Some people here are trying to guess users passwords which is locking the other user out and is now starting to happen to members of staff. To be fair it doesnt take much, just 10 presses of the enter key and they are locked out.

 

Can anyone recommend anything?

 

Thanks

 

Tim

Posted
I believe you should be able to do this by setting an audit policy on the local PC to monitor failed "Logon" events as opposed to "Account Logon". You would then redirect your Event Viewer to remote view the logs of the suspected PC.
Posted
hmmm, i thought of that but it would be nice to know which PC it was the user was trying to logon to, otherwise it means checking every machine that was not in use at that time.
Posted (edited)
In that case monitor failed account logon events on your DCs, then filter the results of the DC event logs. I think you'd be looking for event 529, and the description field would contain the workstation's NetBIOS name. Edited by waldronm2000

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



  • 8 When would you like EduGeek EDIT 2025 to be held?

    1. 1. Select a time period you can attend


      • I can make it in June\July
      • I can make it in August\Sept
      • Other time period. Please comment in the thread what works for you
      • Either time

×
×
  • Create New...