Microsoft has released out-of-band (OOB) Windows updates to address a known issue affecting local audit logon policies in Active Directory Group Policy. "Microsoft has identified an issue where audit logon/logoff events in the local policy of the Active Directory Group Policy might not show as enabled on the device even if they are enabled and working as expected," Microsoft said in a Microsoft 365 admin center update. They are also cumulative, and you do not need to install any previous updates before applying them since they replace all prior updates. The company also added that home users are unlikely to be affected by this known issue since logon auditing is mainly necessary in enterprise environments. As the company explained, these local policy issues might only manifest as a reporting inconsistency since it's possible that logon and logoff events are correctly being audited on some of the affected devices. When enabled, the "Audit logon events" policy setting lets admins decide whether to audit logon and logoff events and generate new entries in the audit logs. On Friday, Microsoft warned admins that some domain controllers running Windows Server 2025 might become inaccessible after a restart, which would cause apps and services to fail. The OOB updates can also be downloaded and installed on affected Windows versions only via the Microsoft Update Catalog.
This Cyber News was published on www.bleepingcomputer.com. Publication date: Mon, 14 Apr 2025 11:55:26 +0000