Hmmm... I've set the security log to audit logon/logoff attempts and I'm
about to set a few other things - key directories etc. Even though I've
refreshed the policy using SECEDIT /REFRESHPOLICY MACHINE_POLICY and
USER_POLICY / enforce, nothing has changed.
When I check the local security settings, audit logon/off is checked, but
the effective policy is no auditing. Checking the Domain Security, auditing
is enabled.
So.. rather puzzled. Can someone help?
Thanks
Admin