This is confusing me to no end and since I've run across a number of Logon
Auditing questions in the training kit I need to get this resolved.
According to the materials, If you configure auditing in the domain security
policy for failed logon events, the events written to the Security log will
be only failed local logon attempts.
Does local logons refer to
a) Using a workstation to log on to the domain using a domain account.
b) Logging on to the workstation using a local account created on that
workstation.
c) Logging on to the domain controller using a domain account.
From what I can tell there are no local domain controller accounts, so I've
left that option out.
|