You can edit the default domain policy to force domain computers to audit both SUCCESS AND FAILURE "Account Logon Events", which are AD accounts, as well as "Logon Events", which are local user accounts.
Local accounts audits are not registered on any DC, only the local computer.
<a href="http://technet.microsoft.com/en-us/library/cc787176(WS.10).aspx">Audit Account Logon Events</a>
<a href="http://technet.microsoft.com/en-us/library/cc787567(WS.10).aspx">Audit Logon Events</a>
Both of these are found in the same GPO Audit Policy location: Computer ConfigurationWindows SettingsSecurity SettingsLocal PoliciesAudit Policy
Last Wiki Answer Submitted: June 16, 2010 8:49 pm by 804TECH95 pts.
If you live outside the United States, by submitting your email address you consent to having your personal data transferred to and processed in the United States.