Windows 2000 has 2 Audit Policy Settings; 1 - Audit account logon events & 2 - Audit logon events
I'm not totally clear on the difference. I know the first one is used as a central repository for auditing logons (e.g., domain account logons to multiple servers can get recorded to the central domain controller log file), but not sure as to second. Does the second setting record successes / failures of local authentication attempts ? Thanks...Mike Ungar --------------------------------------------------------------------------- ----------------------------------------------------------------------------