1) how can i write to a log, or using the system log to check when a user loged in/out from rdp?
2)is there a way to monitor, if a user changed a file and when, and if he stoped/started a service?
10X:)
Page 1 of 1
monitoring activity on server
#2
Posted 17 November 2011 - 08:38 AM
I'm not sure about the second one, but in either case without knowing the exact configuration of your network (you provided generics) the responses you get may not be applicable to your particular setup. As far as #1 here is what I would do.
Have all users who are allowed to use RDP put into the Remote Desktop Users group or a custom OU. Then I would create an Audit Policy to log authentication responses for that group. They would then show up (at least) in the Security section of Event Viewer.
Have all users who are allowed to use RDP put into the Remote Desktop Users group or a custom OU. Then I would create an Audit Policy to log authentication responses for that group. They would then show up (at least) in the Security section of Event Viewer.
#3
Posted 17 November 2011 - 09:53 AM
i have a windows 2008r2 server, that is not a part of a domain!
#4
Posted 17 November 2011 - 05:39 PM
Ok but those users still need to have accounts added to your server in order for them to work with RDP. You can still add those accounts into an OU or the Remote Desktop Users group....
#5
Posted 17 November 2011 - 11:52 PM
On windows 2008R2, default security settings will already log in the eventlogs what you need.
Share this topic:
Page 1 of 1



Help
Back to top










