1.1.2.36 Set 'Audit Policy: Logon-Logoff: Other Logon/Logoff Events' to 'No Auditing'

Information

This subcategory reports other logon/logoff-related events, such as Terminal Services session disconnects
and reconnects, using RunAs to run processes under a different account, and locking and unlocking a workstation.

Solution

Make sure 'Logon-Logoff: Other Logon/Logoff Events' is set to no auditing.

See Also

https://workbench.cisecurity.org/files/17

Item Details

Category: AUDIT AND ACCOUNTABILITY

References: 800-53|AU-12c., CSCv6|16.1

Plugin: Windows

Control ID: 212408bdb2c3cb0f05233ce64d9fbc91fb8774c9d1d8b342a4a56656576901e8