Audit account management

Computer Configuration\Windows Settings\Security Settings\Local Policies\Audit Policy

Description

Determines whether to audit each event of account management on a computer. Examples of account managment events include:

  • A user account or group is created, changed, or deleted

  • A user account is renamed, disabled, or enabled

  • A password is set or changed

By default, this value is set to No auditing in the Default Domain Controller Group Policy object (GPO) and in the local policies of workstations and servers.

If you define this policy setting, you can specify whether to audit successes, audit failures, or not to audit the event type at all. Success audits generate an audit entry when any account management event is successful. Failure audits generate an audit entry when any account management event fails. You can select No auditing by defining the policy setting and unchecking Success and Failure .