[Forgot Password]
Login  Register Subscribe

30389

 
 

423868

 
 

244625

 
 

909

 
 

193379

 
 

277

Paid content will be excluded from the download.


Download | Alert*
OVAL

Audit Policy: Logon-Logoff: Network Policy Server

ID: oval:org.secpod.oval:def:18923Date: (C)2014-05-29   (M)2021-06-02
Class: COMPLIANCEFamily: windows




Auditing of Logon-Logoff: Network Policy Server events on success should be enabled or disabled as appropriate. This subcategory reports events generated by RADIUS (IAS) and Network Access Protection (NAP) user access requests. These requests can be Grant, Deny, Discard, Quarantine, Lock, and Unlock. Auditing this setting will result in a medium or high volume of records on NPS and IAS servers. Events for this subcategory include: Note All the events in the Network Policy Server subcategory are available only in Windows Vista Service Pack 1 and in Windows Server 2008. - 6272: Network Policy Server granted access to a user. - 6273: Network Policy Server denied access to a user. - 6274: Network Policy Server discarded the request for a user. - 6275: Network Policy Server discarded the accounting request for a user. - 6276: Network Policy Server quarantined a user. - 6277: Network Policy Server granted access to a user but put it on probation because the host did not meet the defined health policy. - 6278: Network Policy Server granted full access to a user because the host met the defined health policy. - 6279: Network Policy Server locked the user account due to repeated failed authentication attempts. - 6280: Network Policy Server unlocked the user account. - 8191: Network Policy Server unlocked the user account. Refer to the Microsoft Knowledgebase article Description of security events in Windows Vista and in Windows Server 2008 for the most recent information about this setting: http://support.microsoft.com/default.aspx/kb/947226. Fix: (1) GPO: Computer Configuration\Windows Settings\Security Settings\Advanced Audit Policy Configuration\Audit Policies\Logon/Logoff!Audit Policy: Logon-Logoff: Network Policy Server (2) REG: NO INFO

Platform:
Microsoft Windows Server 2008 R2
Reference:
CCE-10847-2
CPE    1
cpe:/o:microsoft:windows_server_2008:r2
CCE    1
CCE-10847-2

© SecPod Technologies