Either group policy does not have audit controls configured to log the events - or the logons are using cached mode and hence are not occurring. Some things you can check: You are allowing "Domain Computers" to authenticate so that when a domain computer tries to authenticate it can talk to an AD controller rather than having to use cached mode. You haven't got group policy configured to wait for the network for logon causing cached mode to be used. Computer Configuration → Administrative Templates → System → Logon → Always wait for the network at computer startup and logon.
... View more