Tips for finding Knowledge Articles

  • - Enter just a few key words related to your question or problem
  • - Add Key words to refine your search as necessary
  • - Do not use punctuation
  • - Search is not case sensitive
  • - Avoid non-descriptive filler words like "how", "the", "what", etc.
  • - If you do not find what you are looking for the first time,reduce the number of key words you enter and try searching again.
  • - Minimum supported Internet Explorer version is IE9
Home  >

KB-0498: Failed login attempts do not get audited in Security Event Log

Authentication Service ,  

12 April,16 at 11:30 AM


After setting “Success, Failure” for the “Audit account logon events” audit policy (found in Computer Configuration, Windows Settings, Security Settings, Audit Policy), only successful audits are logged in the Security Event Log and not the failure audits.


The audit policy was set at the domain level and not the Domain Controller level. Domain Controller level settings override the domain level settings and by default the domain controller settings are set for only success audits.


Set the same Audit policy, but for the GPO at the Domain Controller level. Once configured, you can run gpupdate at the Command Prompt on the Domain Controller so that it goes into effect immediately.

Still have questions? Click here to log a technical support case, or collaborate with your peers in Centrify's Online Community.