Window server 2012 R2 audit SAM log issue

Copper Contributor

Hi all,

I have a question about the audit log 4661.

I am using advanced audit logging. Enabled audit SAM and audit kernel object which generate event id 4661.

Now I have 2 2012 R2 DC, one is setup without any window update. Another one installed all recommend and important update.

The situation is, when a domain user logged off.

DC without update can generate event id 4661.

DC with updates will not generate event id 4661 but event 4768,4769.

 

What can I do to make the DC with updates generate 4661 when a user is logged off?

 

 

 

0 Replies