Audit Logon Events
Windows 10
To access, do the following
-
Expand Local Policies
-
Expand Audit Policy
-
Double-click Audit logon events
Default values on Client editions:
Logon: Success
Logoff: Success
Account Lockout: Success
IPsec Main Mode: No Auditing
IPsec Quick Mode: No Auditing
IPsec Extended Mode: No Auditing
Special Logon: Success
Other Logon/Logoff Events: No Auditing
Network Policy Server: Success, Failure
Default values on Server editions:
Logon: Success, Failure
Logoff: Success
Account Lockout: Success
IPsec Main Mode: No Auditing
IPsec Quick Mode: No Auditing
IPsec Extended Mode: No Auditing
Special Logon: Success
Other Logon/Logoff Events: No Auditing
Network Policy Server: Success, Failure
Important: For more control over auditing policies, use the settings
in the Advanced Audit Policy Configuration node. For more
information about Advanced Audit Policy Configuration, see
https://go.microsoft.com/fwlink/?LinkId=140969.