DOCUMENT:Q186374 09-AUG-2001 [winnt] TITLE :Enable Auditing of Microsoft Windows NT Server Password Registry PRODUCT :Microsoft Windows NT PROD/VER:winnt:4.0 OPER/SYS: KEYWORDS: ====================================================================== ------------------------------------------------------------------------------- The information in this article applies to: - Microsoft Windows NT Server version 4.0 - Microsoft Windows NT Workstation version 4.0 - Microsoft Windows NT Server, Enterprise Edition version 4.0 ------------------------------------------------------------------------------- SUMMARY ======= Microsoft Windows NT Server operating system includes built-in auditing capability. This allows administrators to track which user account was used to attempt access to files or other objects in an application. Auditing can also be used to track logon attempts, shutdowns or restarts of the system, and similar events. MORE INFORMATION ================ While Windows NT Server has extensive auditing and logging features, some of these are not enabled by default. The following directions will let users turn on logging for password database access. 1. Ensure that auditing is enabled. To do this: a. On User Manager's Policies menu, click Audit. b. Click Audit These Events and then click Close. Auditing may add performance overhead to your system; therefore, you should carefully determine what should be audited and which users and/or groups to audit. Please refer to the book "Windows NT 3.5 Guidelines for Security, Audit, and Control" for an in-depth discussion on the subject. 2. Using the Services tool in Control Panel, start the Scheduler service and ensure that the Startup settings for Scheduler allow the service to be started as System. 3. Open a command prompt and type the following: at