Auditing of 'Account Logon: Kerberos Service Ticket Operations' events on success should be enabled or disabled as appropriate. enabled/disabled (1) Commandline: auditpol.exe (2) GPO: Computer Configuration\Windows Settings\Security Settings\Advanced Audit Policy Configuration\System Audit Policies\Account Logon\Audit Kerberos Service Ticket Operations Microsoft Tool: Security Compliance Manager (SCM) Microsoft Baseline: Windows Server 2008 R2 SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940 oval:org.secpod.oval:def:18752 Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs Microsoft SCAP Repo OVAL Definition 2014-05-29