Steps to Enable Audit logging for NTLM Windows 2008 Domain Controller:
- Login to he Domain Controller box.
- Open a Command line prompt and type in:
- Now you should see the Group Policy Management screen open up. See Screen shot. Expand the Forest>Domains until you get to the "Default Domain Policy".
- Highlight the "Default Domain Policy" and right click on the mouse button. Then click on "Edit". See Screen Shot.
- Now you should have the Group Policy Management Editor screen open for the Default Domain Policy. Now drill down to the Security Options (See screen shot) and then on the right scroll to what is highlighted in red with red arrows.
- Now change the Policy Setting for the three that are highlighted in red in the above screen shot to look like this.
Network security: Restrict NTLM: Audit Incoming Traffic = Enable auditing for all accounts
Network security: Restrict NTLM: Audit NTLM authentication in this domain = Enable all
Network security: Restrict NTLM: Outgoing NTLM traffic to remote servers = Audit All
Steps to collect the NTLM audit logs:
- Open the Event Viewer.
- Expand the Application and Services Logs>Microsoft>Windows>NTLM>Operational
- Now off to the right you will see logging.
Note: If this is first time setting up the NTLM Audit Logging use F5 to refresh the screen.
- Click on Action and scroll down to "Save All Events As..."
- Have customer send a copy of that log.