For this you need follow me in the steps below:
* First: we need create a new Policy and Configure Enable auditing in your Policy.
- Click Start > Administrative Tools > Active Directory Users and Computers.
- In "Active Directory Users and Computers" open window, right click on name of you Domain, and click on Properties.
- In the new open window, click Group Policy tab, click on Open.. button.
- In the "Group Policy Management", click to expand your domain.
- Right click in "Group Policy Objects", and click on New.
- In "New GPO" open window type the name of the new Policy, and click OK.
- Expand "Group Policy Objects", right click on the new created policy, and click to Edit.
- Click to expand Computer Configuration > Windows Settings > Security Settings > Local policy.
- Click to select Audit Policy.
- In the right panel double click on "Audit account logon events".
- In the "Audit account logon events" open windows click to check boxes "Success" and "Failure", then click OK.
- Now double click on "Audit logon events".
- In the "Audit logon events" open windows click to check boxes "Success" and "Failure", then click OK.
- Close The Group Policy Object Editor window.
* Audit logon events: this security setting determines whether to audit each instance of a user logging on to or logging off from a computer.
Now you need will be assigning the policy to an Organizational Unit (OU) containing the computers we wish to have under the policy. For this follow the steps below.
- Click Start > Administrative Tools > Active Directory Users and Computers.
- In "Active Directory Users and Computers" open window, right click on (OU) what do you want to apply the security setting, and click in Properties.
- In the new open window, click Group Policy tab, click on Open.. button.
- In the "Group Policy Managenet" open window is select the (OU), right click in it and select "Link an Existing GPO...".
- Now in "Group Policy objects:" select the new policy created in the first step in this tutorial, and click OK.
- Now in "Group policy Management" open window in the right panel we can see the new policy linked in GPO for this Organizational Unit.