| 
 (Windows 
2008 Server:
Lesson 8){ Setting Up Audit 
Account Logon Events } 
 
			
				| Section 0. 
				Background Information |  
	What are Audit Policies?  
	This feature allows the administrators log 
	events that deal with the following items:
	Audit account logon eventsAudit logon eventsAudit account managementAudit policy changeAudit privilege useAudit system eventsand more... 
			
				| Section 1. Login to 
				your W2K8 server. |  
	Start your Windows 2008 Server
		Instructions: 
		
		
			Click on W2K8 ServerClick on Play virtual machine  CRTL + ALT + DELETE
		Instructions
			Virtual MachineSend Ctrl+Alt+Del  Login as Administrator
	
		Click on the Administrator icon.  Login
		Command: 
		Provide the password for the Administrator account.   
			
				| Section 2. Launching  
				Group Policy Management |  
	Launch Group Policy Management 
		Instructions: 
		
		
			Start --> Administrative Tools --> 
			Group Policy Management
		  Edit Default Domain Controller Policies
		Instructions: 
		
			Navigate to Forest:security.student --> 
			Domains --> security.student --> Domain Controllers.Right Click on Default Domain 
			Controller PoliciesClick on Edit...
		  Navigate to the Audit Policy Section
		Instructions: 
		
			Computer Configuration --> Policies 
			--> Windows 
			Settings --> Security Settings --> Local Policies --> Audit Policy   
			
				| Section 3. Edit 
				Audit account logon events |  
	Edit Audit account logon events
		Instructions: 
		
			Right Click on Audit account logon 
			eventsSelect PropertiesNotes:
		This security setting determines whether to 
		audit each instance of a user logging on to or logging off from another 
		computer in which this computer is used to validate the account.  Configuration Audit account logon events 
	Properties
		Instructions: 
		
		
			Check Define these policy settingsCheck SuccessCheck FailureClick on the Apply Button.Click on the OK Button.   
			
				| Section 4. Edit 
				Audit logon events |  
	Edit Audit logon events
		Instructions: 
		
		
			Right click on Audit logon eventsClick on Properties.Notes: 
		
		
		This security setting determines whether to 
		audit each instance of a user logging on to or logging off from this
		local computer.  Configuration Audit logon events Properties
		Instructions: 
		
		
			Check Define these policy settingsCheck SuccessCheck FailureClick on the Apply Button.Click on the OK Button.   
			
				| Section 5. Edit 
				Audit management events |  
	Edit Audit system events
		Instruction:
			Right click on Audit account management 
			eventsClick on PropertiesNotes:
		This security setting determines whether to 
		audit each event of account management on a computer. Examples of 
		account management events include:
			A user account or group is created, 
			changed, or deleted.A user account is renamed, disabled, or 
			enabled.A password is set or changed.  Configuration Audit account management 
	Properties
		Instructions: 
		
		
			Check Define these policy settingsCheck SuccessCheck FailureClick on the Apply Button.Click on the OK Button   
			
				| Section 6. Edit 
				privilege use events |  
	Edit Audit system events
		Instruction:
			Right click on Audit privilege use 
			eventsClick on PropertiesNotes:
		This security setting determines whether to 
		audit each instance of a user exercising a user right.  Configuration Audit privilege use Properties
		Instructions: 
		
		
			Check Define these policy settingsCheck SuccessCheck FailureClick on the Apply Button.Click on the OK Button     
			
				| Section 7. Edit 
				policy change events |  
	Edit Audit system events
		Instruction:
			Right click on Audit policy change 
			eventsClick on PropertiesNotes:
		This security setting determines whether to 
		audit every incident of a change to user rights assignment policies, 
		audit policies, or trust policies.  Configuration Audit policy change Properties
		Instructions: 
		
		
			Check Define these policy settingsCheck SuccessCheck FailureClick on the Apply Button.Click on the OK Button   
			
				| Section 8. Update 
				Group Policies |  
	Bring up a command prompt
		Instruction:
			Start --> Command Prompt  For Update
		Instruction:
			gpupdate /forceNote:
			The "gpupdate" utility will update 
			group policies.
		   Restart the server
		Instruction:
			Start --> Restart     
			
				| Section 9. Create 
				two failed logon attempts |  
	CRTL + ALT + DELETE
		Instructions:
			Virtual MachineSend Ctrl+Alt+Del  Create failed logon attempt #1
		Instructions: 
		
		
			Supply the wrong password.Press Enter  Press the OK Button
		Instructions: 
		
		
			Click the OK Button  Create failed logon attempt #2
		Instructions: 
		
		
			Supply the wrong password.Press Enter  Press the OK Button
		Instructions: 
		
		
			Click the OK Button  Provide the correct password
		Instructions: 
		
		
			Supply the correct password.  Open the Event Viewer
		Instructions: 
		
		
			Start --> Administrative Tools --> 
			Event Viewer  Navigate to the security logs
		Instructions: 
		
		
			Windows Logs --> SecurityLook for the failed logon attempts   
	Bring up a command prompt
		Instruction:
			Start --> Command Prompt  Using the gpresult utility
		Instruction:
			gpresult /V | more
			Before you press the <Enter> 
			key more than once, continue to the next step.Note:
		Displays Group Policy settings and 
		Resultant Set of Policy (RSOP) for a user or a computer. (See 
		More)
		   Using the gpresult utility
		Instruction:
			Keep pressing the <Enter> key until you 
			see "User Rights"Once you see "User Rights" press the 
			<Ctrl>+c keysdatePress Enterecho "Your Name"
				Replace the string "Your Name" with 
				your actual name.E.g., echo "John Gray"
		Proof of Lab Instruction:
			Do a PrtScnPaste into a word documentUpload to Moodle. | 
    
 
   
		
		
		 |