Hi all,
I am monitoring user access events, Event Ids: 4768
They appear on the Event viewer under Windows Logs - Security - Audit Success
e.g for 4768:
TargetDomainName MOSHE
Sometimes the TargetDomainName is MOSHE (Netbios) and sometimesTargetDomainName is MOSHE.com.
How can i enforce it to be only 1 unique thing? MOSHE and MOSHE.com, Its the same domain controller/domain.
The user join RDP session sometimes with .com and sometimes without. I want on both cases to have same Supplied realm name - is this possible?