I've searched for this answer but can't seem to find it. I do I set auditing for administrator logons only, when I set auditing up for logons, it gets everyone. I know this has to be easy, but I can't seem to find it.
I created an OU called administrative accounts, moved my two administrator users into that OU. Right clicked on OU, properties, group police, new, edit...
Clicked on Security, gave authenticated users and administrators full control.
Checked no override.
Logged out, logged back in as administrator, no events. I know auditing works, I set it up as a domain security policy, but it logged everybody.. don't want that, only administrator.
I've read everypost I can find on this subject and I can't find anything different than what I've done above...
This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
By continuing to use this site, you are consenting to our use of cookies.