Score:-1

Why fresh installed Windows 10 VM generates 4624/4625 whereas Audit account logon events is set to "No auditing" in Audit Policy

ua flag

All is in the title. By the way, each policies are set to "No auditing" in Audit Policy by default but we still get events in the Event Viewer. I don't understand how.

Score:0
cn flag

You may have configured legacy audit policies. Those are not used by default. The audit policies are configured under Windows Settings\Security Settings\Advanced Audit Policy configuration.

ua flag
Thank you for your feedback. I did not configure anything. I just installed a Win10 VM and realized that a lot of events are enabled by default and it does not match what I see in the Audit Policy. If I open "Local Security Policy" and go to "Security Settings \ Advanced Audit Policy\System Audit Policies - Local Group Policy Object\Logon/Logoff", I get all subcategory to "Not Configured"
ua flag
But in the "Explain" tab from "Properties" its says "Default on Client editions: Success." So maybe that means that if you do not configure anything, it put this value by default. It would explain 4624 but not 4625 :/
cn flag
If `auditpol /get /category:*` shows it enabled, it would need to be configured in the policy to change it.
ua flag
I executed your command. I got "No Auditing" for all "Logon/Logoff" category
ua flag
Oops now I don't get any 462[4|5] anymore. Maybe I've changed something during my manipulations. Thank you for your clarifications though.
mangohost

Post an answer

Most people don’t grasp that asking a lot of questions unlocks learning and improves interpersonal bonding. In Alison’s studies, for example, though people could accurately recall how many questions had been asked in their conversations, they didn’t intuit the link between questions and liking. Across four studies, in which participants were engaged in conversations themselves or read transcripts of others’ conversations, people tended not to realize that question asking would influence—or had influenced—the level of amity between the conversationalists.