Re: IWAM account

From: Andrew Davis [MS] (adavis_at_online.microsoft.com)
Date: 12/17/03


Date: Wed, 17 Dec 2003 16:09:28 GMT

Check the user right "logon as batch", and add the iwam account to have
this user right. This should take care of your problem.

This appears to be a negotiate failure due to logon as batch.
http://support.microsoft.com/?id=326985

Logon Type A numeric value indicating the type of logon attempted.
Possible values are:
2 - Interactive (interactively logged on)
3 - Network (accessed system via network)
4 - Batch (started as a batch job)
5 - Service (a Windows service started by service controller)
6 - Proxy (proxy logon; not used in Windows NT or Windows 2000)
7 - Unlock (unlock workstation)
8 - NetworkCleartext (network logon with cleartext credentials)
9 - NewCredentials (used by RunAs when the /netonly option is used)

This posting is provided "AS IS" with no warranties, and confers no rights.

Thanks!
~Andrew Davis
Microsoft PSS Security

--------------------
| From: Paul Lynch <paul.lynch@nospam.com>
| Subject: Re: IWAM account
| Date: Tue, 16 Dec 2003 11:53:58 +0000
| Message-ID: <ahsttvk6klr8aeq1s5462tqhni4j7j15ld@4ax.com>
| References: <090401c3c341$bf719b50$a001280a@phx.gbl>
| X-Newsreader: Forte Agent 1.93/32.576 English (American)
| MIME-Version: 1.0
| Content-Type: text/plain; charset=us-ascii
| Content-Transfer-Encoding: 7bit
| Newsgroups: microsoft.public.inetserver.iis.security
| NNTP-Posting-Host: host81-133-143-93.in-addr.btopenworld.com 81.133.143.93
| Lines: 1
| Path:
cpmsftngxa07.phx.gbl!cpmsftngxa06.phx.gbl!cpmsftngxa09.phx.gbl!TK2MSFTNGP08.
phx.gbl!tk2msftngp13.phx.gbl
| Xref: cpmsftngxa07.phx.gbl microsoft.public.inetserver.iis.security:7913
| X-Tomcat-NG: microsoft.public.inetserver.iis.security
|
| On Mon, 15 Dec 2003 11:29:24 -0800, "Chuck"
| <anonymous@discussions.microsoft.com> wrote:
|
| >I upgraded to WinXP last week and installed IIS. When I
| >try to run my web app (Java Applet and lots of ASP), I
| >get the following error logged in EventViewer:
| >Event Type: Failure Audit
| >Event Source: Security
| >Event Category: Logon/Logoff
| >Event ID: 534
| >Date: 12/15/2003
| >Time: 1:18:10 PM
| >User: NT AUTHORITY\SYSTEM
| >Computer: <computer name>
| >Description:
| >Logon Failure:
| > Reason: The user has not been granted the
| >requested
| > logon type at this machine
| > User Name: IWAM_<computer name>
| > Domain: <computer name>
| > Logon Type: 4
| > Logon Process: Advapi
| > Authentication Package: Negotiate
| > Workstation Name: <computer name>
| >
| >---
| >When I first installed IIS, I was able to hit a testing
| >web app (basic ASP) with no problem. When I try to hit
| >the real web app, the browser hangs. Cycling IIS usually
| >hangs so I have to reboot. After that, I can't even hit
| >the test site again. Any help would be greatly
| >appreciated.
| >
| >Thanks,
| >--Chuck
|
| Chuck,
|
| Try these articles :
|
| Domain Controller Demotion Causes Out-of-Process Applications to Fail
| http://support.microsoft.com/?id=236007
|
| Event ID 36 - The server process could not be started because the
| configured identity is incorrect
| http://www.iisfaq.com/default.aspx?View=A464&P=123
|
|
| Regards,
|
| Paul Lynch
| MCSE
|



Relevant Pages

  • Re: Sudden and repeated launching of cmd.exe and net.exe
    ... earlier suggestion to check the Task Scheduler for a batch ... and changing it to run only at logon. ... I will put the two kill commands on my ... >The Task manager will also display process users names ...
    (microsoft.public.win2000.cmdprompt.admin)
  • Re: Scheduled Task wont run unless use Admin account
    ... When you said "You may need to add the user/ group 'logon as batch job' ... and Bypass Traverse Checking directly to the desired account, ... If I am interactively logged in as the target account, ...
    (microsoft.public.windows.server.general)
  • Re: Scheduler Failed
    ... The log on as batch files I already try before. ... > 'logon as batch job' rights. ...
    (microsoft.public.win2000.general)
  • Unusual logon / logoff Security event log
    ... Another preculiar is for example event ID 540, On the event id, the logon ... On the webpage, type 3 is network, type 4 is batch. ...
    (microsoft.public.windows.server.sbs)
  • Copying files based on date during logon
    ... I am a scripting neophte, to put it in a nice fashion... ... I have a batch file that is called via GPO during the logon ... which copies a file from a network location to the ...
    (microsoft.public.windows.server.scripting)

Loading