Windows 2000 has 2 Audit Policy Settings;

1 - Audit account logon events &
2 - Audit logon events

I'm not totally clear on the difference. I know the
first one is used as a central repository for auditing
logons (e.g., domain account logons to multiple
servers can get recorded to the central domain
controller log file), but not sure as to second. Does
the second setting record successes / failures of
local authentication attempts ?

Thanks...Mike Ungar


Reply via email to