locked
Win2003 Server - Security Event Log doesn't log down the account management event RRS feed

  • 問題

  • Hello Professional,

    We are using Windows 2003 Server, in Active Directory Users and Computers, enable the Audit policy of account management for the domain.

    We have done a lot of account create, delete, reset password etc, but none of the activity can be found in the event log.

    Any idea?

    Thanks a lot.

    Have a good weekend.

    Jack
    2009年8月21日 上午 07:33

所有回覆

  • Dear Customer,

     

    Based on my research, I understand that audit policy which Computer Account is used by user when logon. Technically, we can archive this goal by enabling “Audit Policy” settings in Default Domain Controllers Policy.
     

    Hope this helps.


    If there are any concerns and questions on the above, please feel free to let me know.


    Sincerely,

     

    Tom Zhang


    Tom Zhang – MSFT
    2009年8月21日 上午 09:13
    版主
  • Hi Tom,

    Before I opened this thread, I have done exactly what you are talking about. I enabled Audit policy setting in Default Domain Controller policy.

    The strange thing is I have couple domains in my company, this case is happened in one domain only, other domains work fine for the account management audit.

    So...the question is.....why I have done the user account changed, but the event didn't appear in both GC and DC?

    Jack
    2009年8月21日 下午 01:58