Skip to main content

Enabling logon audit Policy

Ever wandered who logged on and when on a windows PC or server ?
This is not enabled by default, here is how to enable it :

  1. Type gpedit.msc
  2. Navigate to the following folder: Local Computer Policy –> Computer Configuration –> Windows Settings –> Security Settings –> Local Policies –> Audit Policy.
  3. Double click the auto logon events
  4. Enable both
  5. You can view all those extra events from now on in the event log under : ID 4624






I am the one