17.5.4 Set 'Audit Other Logon/Logoff Events' to 'Success and Failure'

Information

This subcategory reports other logon/logoff-related events, such as Terminal Services session disconnects and reconnects, using RunAs to run processes under a different account, and locking and unlocking a workstation.

Events for this subcategory include: - 4649: A replay attack was detected.

- 4778: A session was reconnected to a Window Station.

- 4779: A session was disconnected from a Window Station.

- 4800: The workstation was locked.

- 4801: The workstation was unlocked.

- 4802: The screen saver was invoked.

- 4803: The screen saver was dismissed.

- 5378: The requested credentials delegation was disallowed by policy.

- 5632: A request was made to authenticate to a wireless network.

- 5633: A request was made to authenticate to a wired network.

The recommended state for this setting is: 'Success and Failure'.

Solution

To establish the recommended configuration via GP, set the following UI path to 'Success and Failure':

Computer Configuration\Policies\Windows Settings\Security Settings\Advanced Audit Policy Configuration\Audit Policies\Logon/Logoff\Audit Other Logon/Logoff Events

See Also

https://workbench.cisecurity.org/files/1941