NTLM Audit Log investigation
Gopi Ponnusamy
46
Reputation points Microsoft Employee
Hi Guys,
I have enable the NTLM audit in Domain controllers and i got the below logs on Microsoft-Windows-NTLM/Operational
Domain Controller Blocked Audit: Audit NTLM authentication to this domain controller.
Secure Channel name: Print1
User name: Rohit$@jayjay6734 .com
Domain name: lab.com
Workstation name: Client1
Secure Channel type: 2
can anyone help me to understand this logs.
Windows for business | Windows Client for IT Pros | Directory services | Active Directory
Sign in to answer