<p>Via GPO :</p>
<ol>
<li>Éditez la Default Domain Controllers Policy</li>
<li>Naviguez vers Computer Configuration > Policies > Windows Settings > Security Settings > Advanced Audit Policy Configuration</li>
<li>Activez les catégories souhaitées :
<ul>
<li>Account Logon > Audit Kerberos Authentication Service</li>
<li>Account Logon > Audit Credential Validation</li>
<li>Logon/Logoff > Audit Logon</li>
</ul>
</li>
</ol>
<p>Ou avec l’ancienne méthode :<br>
Computer Configuration > Policies > Windows Settings > Security Settings > Local Policies > Audit Policy</p>
<ul>
<li>Audit account logon events : Success, Failure</li>
<li>Audit logon events : Success, Failure</li>
</ul>