Skip to main content
Role AvailabilityRead-OnlyInvestigatorAnalystManager
This Windows Authentication dashboard displays data when your environment includes Microsoft Windows security auditing events. Widgets in the Windows Authentication Dashboard
WidgetsDescription
Logon Session EventsDisplays the logon session events like successful logon, user initiated logoff, logon failure, remote desktop session reconnected/disconnected, workstation locked/unlocked, and screen saver invoked/dismissed.
Logon typesDisplays the logon types like interactive, network, batch, service, unlock, network cleartext, remote desktop, and logon with cached credentials.
Domain Controller Authentication EventsTop authentication events received by the Domain Controller. For example: Kerberos tickets of any type (authentication, services).
Logon Failure ReasonsTop logon failure reasons in the Active Directory. For example: incorrect usernames or bad passwords.
Kerberos Failure CodesTop error codes generated by Kerberos service. For example: errors received during authentication and service requests.
Ticket Encryption TypePie chart containing the different encryption types used in Kerberos. For example: DES, RC4, AES, etc.
Ticket Pre-Authentication TypePie chart containing the different Pre-Authentication types used in Kerberos. For example: timestamp, salt, etc.
Authentication PackageTop Active Directory authentication packet types. For example: Kerberos or NTLM.
User Account ChangesDisplays the user account changes like created, enabled, disabled, deleted, etc.
Group ChangesDisplays the group changes like created, changed, deleted. It also displays if a member has been added or removed.
Remote Desktop SessionsSankey diagram containing remote connections between the different users and destination hosts.
I