Skip to main content

Enabling logon audit Policy

Ever wandered who logged on and when on a windows PC or server ?
This is not enabled by default, here is how to enable it :

  1. Type gpedit.msc
  2. Navigate to the following folder: Local Computer Policy –> Computer Configuration –> Windows Settings –> Security Settings –> Local Policies –> Audit Policy.
  3. Double click the auto logon events
  4. Enable both
  5. You can view all those extra events from now on in the event log under : ID 4624

650x560ximage104.png.pagespeed.ic.AVT_mwOj6c222650x554ximage105.png.pagespeed.ic.JOYH8AUupk

3650x452ximage108.png.pagespeed.ic.A7hGupmT_K

 

 

upggr

I am the one