Table of Contents

NIOS User-ID

When using NIOS Identity Mapping, you need Kerberos auditing logs to be enabled on the domain controllers to get event_id 4624, event_id 4634 plus others.

event_id: 4624 identifies the user, IP address, first seen and last seen

Microsoft Configuration

First of all, check your auditing settings:

  1. In the Group Policy Management Editor → Computer Configuration → Policies → Windows Settings → Security Settings → Local Policies → Audit Policy. Set the following audit policies:
    • Audit account management: “Success”
    • Audit directory service access: “Success”
    • Audit logon events: “Success” and “Failure”
    1. Alternatively, you can set Advanced audit policies: In the Group Policy Management Editor → Computer Configuration → Policies → Windows Settings → Security Settings → Advanced Audit Policy Configuration → Audit Policies. Set the following audit policies:

NIOS Configuration