RDP Authentication vs. Authorization

Поделиться
HTML-код
  • Опубликовано: 27 дек 2024
  • НаукаНаука

Комментарии • 11

  • @EddyGurge
    @EddyGurge 11 месяцев назад +1

    Love learning new tidbits like this! Keep them coming!

  • @Vic-dl7wq
    @Vic-dl7wq 11 месяцев назад +4

    How do you determine authorization failed?

    • @13Cubed
      @13Cubed  11 месяцев назад +6

      Event ID 4825 is usually helpful there.

    • @Lot13Prophet
      @Lot13Prophet 11 месяцев назад +3

      In addition to @13Cubed's response, you'll want to make sure your audit policy for Logon/Log off -> Other login/log off events is enabled for failed and successful events (ideally enforced through GPO in the default domain policy or a baseline Intune policy) if you want that log to be generated on the local system. Check your SIEM config to ensure those event types aren't being filtered.

    • @dyarizadeh3
      @dyarizadeh3 11 месяцев назад +3

      Had the same question, thanks for asking!

  • @admar-nelson
    @admar-nelson 8 месяцев назад +1

    Very informative and clear to understand. brilliant thanks

  • @redmockingbird4704
    @redmockingbird4704 11 месяцев назад +2

    This is simply brilliant - thank you for this amazing video

  • @ronoazoro9060
    @ronoazoro9060 10 месяцев назад

    what about dameware ?

    • @13Cubed
      @13Cubed  10 месяцев назад

      There are dozens and dozens of remote support tools, each with their own artifacts and caveats. I will consider making future episodes covering some of them in the future.

  • @MrNerdKaiser
    @MrNerdKaiser 11 месяцев назад

    This is great information - thanks!

  • @andrevm9410
    @andrevm9410 11 месяцев назад

    Not complicated but very usefull. Thanks!