You are using an out of date browser. It may not display this or other websites correctly. You should upgrade or use an alternative browser.
windows ad
About this tag
Windows AD (Active Directory) event monitoring is a common topic in WindowsForum discussions, particularly around security auditing. Users often seek to interpret Windows security events 4624 and 4625 to detect interactive logon types (such as type 2 or type 10) for identifying malicious activity. Challenges arise when event logs do not reflect the expected logon type, as seen when interactive logons appear as type 3 instead. The community explores whether Group Policy or AD configuration changes can enforce more accurate logging. These discussions focus on practical troubleshooting for IT professionals managing Windows AD environments and enhancing security monitoring without third-party SIEM integration.
Hello All,
Greetings!!!
In our environment we monitor windows events 4624 and 4625 on AD for other workstations as all workstations can not integrated in a SIEM.
However, in event 4624 and 4625, we are not getting any type 10 or type 2 logon type that could tell us the interactive logon has...