I have auditing for Logon events enabled on my Domain Controller Group policy. But, when I run RSOP.msc I see red "X"s on all the audit policies. If I look at properties on the logon event, then look as the precedence tab, I see this error "The policy engine did not attempt to configure the setting. For more information, see %windir%\security\logs\winlogon.log on the target machine." I looked at this directory on the DC, but it doesn't exist. There are no logon events being logged by the DCs either. How can I troubleshoot this issue? Thanks! ![73027-image.png][1] [1]: /answers/storage/attachments/73027-image.png