how can I do that ?
Can you see it in in local security log? Then run a ACS report for the same
event ID. Do you know which event ID it is?
You can also try run the report for all events for a user ID.
"ERG" <E...@discussions.microsoft.com> wrote in message
news:247B88F5-B211-4571...@microsoft.com...