Auditing Logon Failures for Win2K clients in a NT Domain

From: Jane Lecian (Jane.Lecian@analexcleveland.com)
Date: 10/07/02


From: Jane.Lecian@analexcleveland.com (Jane Lecian)
Date: 7 Oct 2002 11:35:27 -0700


Hello All,

I have discovered a problem in our production domain. It is a NT 4.0
domain with NT 4.0 with sp6a on the DC's. We have converted all of
the clients in Win2K with sp2. We have auditing of both logon
successes and failures enabled on the DC's. When a user from a Win2K
workstation mistypes the password, nothing is logged to the security
log on the DCs. From the old security logs prior to the workstation
upgrade, we were getting Event ID 529's in the Security event log when
a user mistyped a password.

If the Win2K user mistypes the password enough times to lock out his
account, we do get an Event ID 644 in the security log, but still no
Event ID 529's are logged.

As a test I did enable Audit Logon Events (both failure & success) on
a workstation, and then mistyped the password. The local workstation
security event log does show a 529 error, but I really want the error
message to show in the DC's event logs. It is not practical (or maybe
even possible) to periodically check the event logs on all the
workstations in the domain on a periodic basis.

I have duplicated this behavior on a small test network that I set up.
A single NT 4.0 PDC, & 1 Win2K workstation.

I have been unsuccessful at locating any information in MS Knowledge
Base on this problem. I have only found Q172402 Auditing Logon
Failures Does Not Log Remote Failures which refers me to Q182918 which
says the "Microsoft recommends that you install Windows NT 4.0 Service
Pack 4 to correct this problem". As we are running sp6a and I
understand that service packs are cumulative, I feel that there must
be another solution I am looking for. To be on the safe side, I did
reinstall sp6, but it did not resolve the problem.

Can someone kindly point me the right direction to the solution? I am
sure that I am overlooking something simple.

Thanks,

Jane Lecian



Relevant Pages

  • Event Log Export or Analyzer
    ... I've exported the Security Event Log but did not get the "Source ... Workstation". ... Then I did a Save As and got the detail in a csv files but it ... is there a "better" event log analyzer than just the event viewer? ...
    (microsoft.public.windows.server.general)
  • RE: Weird 529 Errors in Security Log
    ... 1: Install latest service pack for workstation and SBS server: ... In order to reset the machine account password of a domain controller use: ... click to check the "Hide All Microsoft Services" ... Save the application event log and system event log as evt files on the ...
    (microsoft.public.windows.server.sbs)
  • Re: Event ID 537
    ... Nothing on workstation has changed, although I have recently applied SP1 for the SBS2003 server. ... I have around 2000-3000 errors in my event log. ... An error occurred during logon ...
    (microsoft.public.windows.server.sbs)
  • RE: Internet connection stops responding two
    ... I am having the exact same problem, desktop dell with wireless connection - I ... > I get one error in the System Event Log and three in the Security Events Log ... > Security Event Log ... IPSec Services could not be started. ...
    (microsoft.public.windowsxp.network_web)
  • Internet connection stops responding two
    ... Running XP SP2 On a Dell Dimension 8200 with Dial-up connection. ... I get one error in the System Event Log and three in the Security Events Log ... The IPSEC Services service terminated with the following error: ... Security Event Log ...
    (microsoft.public.windowsxp.network_web)