How to audit account logon events across AD domains. Whether you're investigating a credential attack or maintaining compliance across client environments, the quality of your audit data determines how fast and accurately you can respond. In this video, we're walking through a six-step framework for setting up, centralizing, and operationalizing AD logon auditing at scale. Before we begin, be sure to subscribe to NinjaOne's IT Video Hub and our YouTube channel for more tech content like this. How to audit AD account logon events. Distinguish between account logon and logon/logoff events. First, make sure your team is working from the same definitions. Audit account logon events track credential validation on domain controllers. The key event IDs here are 4768 for TGT issuance and 4776 for NTLM failures. Audit logon and logoff events, on the other hand, track session creation on the local machine. Those key event IDs are 4624 for a successful logon and 4625 for a failed one. Configure and verify audit policies via Group Policy. The next step is making sure Windows is actually capturing the right events consistently across your environment. On domain controllers, use a GPO to enable audit credential validation for both success and failure under Advanced Audit Policy. On workstations and servers, apply a separate GPO to the relevant OUs to enable audit logon for success and failure. After running GPUpdate /force, verify the policies are working by checking ADC for event 4776 and an endpoint for event 4624. Centralize logs and plan retention. Without centralization, correlation across systems becomes manual and slow. Start by significantly increasing the security log maximum size on domain controllers and key servers to reduce the risk of critical events being overwritten before they're collected. Then, implement a central collection point, either Windows Event Forwarding for a native solution or SIEM connectors if you're pulling logs into a dedicated platform. Build high-signal queries and correlations. Target security-critical patterns, spikes in 4776 NTLM failures on DCs, 4625 logon failures on endpoints, or successful 4624 logons occurring outside business hours. Next, build correlation queries that link DC authentication events like 4768 with endpoint session events like 4624, using common fields such as user, source IP, and time to reconstruct complete user sessions. Operationalize at a multi-tenant scale. Standardize policy deployment using automated group policy baselines with health checks to catch configuration drift early. Build a repeatable onboarding process for your SIEM or Windows Event Forwarding infrastructure, including health monitoring for all data collectors. Don't forget to keep clients informed by automating a per-tenant monthly report that shows auditing coverage and key metrics. Remediate and govern identities. The last step is closing the loop between detection and remediation. Investigate repeated 4771 and 4776 failures and reset or disable compromised accounts. Use your audit data to identify dormant or overprivileged admin accounts and remove unnecessary privileges or decommission unused accounts. Document all changes in an access register and verify that remediation actually reduces alert noise over time. Effective AD logon auditing isn't a one-time configuration. Get your event definitions right, enforce consistent policies through Group Policy, centralize your logs, build meaningful detections, standardize across tenants, and act on what you find. For more information, check out our official blog post on how to audit account logon events across AD domains, linked in the description below.

How to Audit Account Logon Events Across AD Domains

Auditing account logon events across Active Directory domains is critical for detecting unauthorized access and maintaining compliance. This video walks through configuring audit policies, interpreting event IDs, and correlating logon data across multi-domain environments for consistent visibility. 

Read the full blog on How to Audit Account Logon Events Across AD Domains

Never miss a NinjaOne video!