You can edit the default domain policy to force domain computers to audit both SUCCESS AND FAILURE "Account Logon Events", which are AD accounts, as well as "Logon Events", which are local user accounts.
Local accounts audits are not registered on any DC, only the local computer.
<a href="http://technet.microsoft.com/en-us/library/cc787176(WS.10).aspx">Audit Account Logon Events</a>
<a href="http://technet.microsoft.com/en-us/library/cc787567(WS.10).aspx">Audit Logon Events</a>
Both of these are found in the same GPO Audit Policy location: Computer ConfigurationWindows SettingsSecurity SettingsLocal PoliciesAudit Policy
Last Wiki Answer Submitted: June 16, 2010 8:49 pm by 804TECH95 pts.