Re: Event 643 in Security log every 5 minutes

From: Steven L Umbach (n9rou_at_n0-spam-for-me-comcast.net)
Date: 07/10/04


Date: Sat, 10 Jul 2004 18:55:13 GMT

By default, Group/security policy is refreshed every five minutes on a domain
controller. Possibly that computer is having a problem with a change in password
policy being applied. I would first run netdiag on it and then dcdiag on it to see if
it reports any failed tests/errors/fatal warnings that would indicate a problem with
replication, sysvol, dns, etc. In addition run gpotool to see if it reports any
errors in policy synch between the domain controllers. Those tools are on the
install disk in the support tools folder where you need to run setup to install the
set. --- Steve

"Steven T" <guess_what@hkem.com> wrote in message
news:%238OWAkiZEHA.1764@TK2MSFTNGP10.phx.gbl...
> Here's what happened.
> In the AD, there are 2 domain controllers, both are running W2K Server w/SP4
> In the event log of the First DC(which holds all the FSMO roles), event id
> 643 appeared
> every 5 minutes for the whole day. It act as a File server as well as a
> print server. It is located in a closed network and no one using
> the network should have a user right more than an ordinary domain user.
> The holder of the adminitrator account(The companies' Vice President) have
> no
> physical access to the network. No tasks were scheduled to run every 5
> minutes.
> And the strange thing is, the events does not appear in the other domain
> controller.
> Can anyone suggest a possiblity of what's happening??
> I searched through TechNet and could find no clue of this...
> Thank you.
>
> Below is an extract of the event log:
> 7/8/2004 12:01:09 AM 8 7 643 Security NT AUTHORITY\SYSTEM DC1 Password
> Policy DOMAIN %{S-1-5-21-602162358-1644491937-682003330} DC1$ DOMAIN
> (0x0,0x3E7) -
> 7/8/2004 12:06:26 AM 8 7 643 Security NT AUTHORITY\SYSTEM DC1 Password
> Policy DOMAIN %{S-1-5-21-602162358-1644491937-682003330} DC1$ DOMAIN
> (0x0,0x3E7) -
> 7/8/2004 12:11:34 AM 8 7 643 Security NT AUTHORITY\SYSTEM DC1 Password
> Policy DOMAIN %{S-1-5-21-602162358-1644491937-682003330} DC1$ DOMAIN
> (0x0,0x3E7) -
> 7/8/2004 12:16:41 AM 8 7 643 Security NT AUTHORITY\SYSTEM DC1 Password
> Policy DOMAIN %{S-1-5-21-602162358-1644491937-682003330} DC1$ DOMAIN
> (0x0,0x3E7) -
> 7/8/2004 12:21:48 AM 8 7 643 Security NT AUTHORITY\SYSTEM DC1 Password
> Policy DOMAIN %{S-1-5-21-602162358-1644491937-682003330} DC1$ DOMAIN
> (0x0,0x3E7) -
> 7/8/2004 12:26:55 AM 8 7 643 Security NT AUTHORITY\SYSTEM DC1 Password
> Policy DOMAIN %{S-1-5-21-602162358-1644491937-682003330} DC1$ DOMAIN
> (0x0,0x3E7) -
>
>



Relevant Pages

  • Re: Userenv 1030 and 1058 errors! Please help me!
    ... For information about network troubleshooting, see Windows Help. ... Windows cannot query for the list of Group Policy objects. ... Check the event log for possible messages previously logged by the policy engine that describes the reason for this. ...
    (microsoft.public.windows.server.general)
  • Re: Tektronix Phaser 850, wie den USB-Anschluss konfigurieren?
    ... Wenn gefunden, auf "Enabled" stellen! ... System Time: [geschenkt] ... Diskette Controller: ... Event Log capacity: Space Available ...
    (de.comp.hardware.drucker)
  • Re: Whats happening ? Group Policy problem
    ... When I was applying some Computer group policy in my domain (domain ... I have a client machine as well as a windows 2003 server ... added a group policy in the domain controller which has the authenticated ...
    (microsoft.public.win2000.active_directory)
  • Re: Recover from log on locally domain setting
    ... >Changing the domain policy for logon locally should NOT ... >controller - preferrably the pdc fsmp role holder. ... overriding the domain GPO. ... >> So the system is taking the domain security policies. ...
    (microsoft.public.win2000.security)
  • Re: Default Domain Controller Policy being overwritten
    ... I do have the event log size defined. ... the log file and filling up in a few days. ... It's almost like I change the policy on the ... >> errors relating to this in the event logs on either domain controller. ...
    (microsoft.public.windows.server.active_directory)