Re: auditing

From: Steven L Umbach (n9rouz_at_nscomcast.net)
Date: 11/20/03

  • Next message: anonymous_at_discussions.microsoft.com: "LSASS.exe - error on boot up"
    Date: Thu, 20 Nov 2003 22:59:19 GMT
    
    

    You would have to enable auditing of logon events for domain machines. You may want
    to only enable auditing of failures on domain computers that are not resource
    servers. Then you would have to scan the security logs in Event Viewer for the failed
    logon attempts using your account. You can do that on a large scale with third party
    tools or try Event Comb from Microsoft. The failed logon attempts could be logging
    onto the domain or trying to access network shares which could include the
    administrative share on any domain computer. Keep in mind that it may not be
    malicious. Many times this will happen if a user is logged onto another machine, a
    mapped drive, service account, Scheduled Task, or anywhere else your credentials are
    being used and the your password has changed. See links below for more info. ---
    Steve

    http://support.microsoft.com/default.aspx?scid=kb;en-us;300549
    http://support.microsoft.com/default.aspx?scid=KB;en-us;q300958
    http://tinyurl.com/vtyv
    http://tinyurl.com/a5zj -- Read the white paper here also.

    "brian" <anonymous@discussions.microsoft.com> wrote in message
    news:28db01c3af94$6c019710$a601280a@phx.gbl...
    > Hi. I believe that someone is using my account because my
    > account keeps getting locked out. Anyone know of a way to
    > see if someone is attempting to log on with my account,
    > from what pc and at what time? I'm sure there's a way to
    > do it via the event viewer, not sure how to do it on a
    > domain wide scale.
    >
    > thx


  • Next message: anonymous_at_discussions.microsoft.com: "LSASS.exe - error on boot up"

    Relevant Pages

    • Re: logon/power-users group question
      ... users to the power users group (via My computer>Properties>Computer ... and then logon to the computer with that account to bypass domain ... > You can limit logon to domain computers in a couple of ways. ...
      (microsoft.public.windows.server.security)
    • Re: Authenicated Users Query
      ... If the account that the user is logged onto on the non domain computer has ... If you have auditing of logon events enabled ... use ipsec AH/ESP for communications with domain computers but otherwise it ...
      (microsoft.public.windows.server.security)
    • [EC-SA-01.2003] Windows XP "welcome screen" exposes the names of all the members of the l
      ... logon screen with what is called "Welcome Screen". ... (including the original administrator account, ... Using the "welcome screen" actually disables / ignores the security ...
      (Bugtraq)
    • Re: ATTN : Microsoft - Security Event 529....Second Request for help....
      ... According to the events, the logon ... failure is from the local machine account. ... disconnected from the network. ... Security Event ID 529 is a failure audit for logon/logoff. ...
      (microsoft.public.windows.server.sbs)
    • Re: Windows server 2008 R2 freezes
      ... I don't know any free AV for server versions. ... But this can also be used during logon, ... Actually at 11.00 pm the backup was started. ... Account Domain: NT AUTHORITY ...
      (microsoft.public.windows.server.general)