Oodles of 529 Logon Failures every 2:00 AM

From: Lisa_at_work (anonymous_at_discussions.microsoft.com)
Date: 08/29/04


Date: Sun, 29 Aug 2004 12:09:35 -0700

Hello, when this same thing was happening to us it was the
backup agent for Veritas which was trying to authenticate
a service account on all servers at once. It was a local
service admin account which authenticated to the domain by
creating an account with the same username / password in
AD. When the AD password expired this same thing happened.
We reset the AD password and set it to "never expire" and
that fixed it. Hope this helped.

Lisa

>-----Original Message-----
>Hello,
>
>My Windows 2000 domain is getting an error every night at
2AM because it
>can't lock out the Administrator account. Yes,
exactly; "why is it being
>told to lock out in the first place?" I don't think
we're under attack
>because it is every night at the same time and because I
have found some
>information which may shed some light on it.
>
>It seems that at 2:00 AM some process happens that all of
the local
>administrator accounts on the servers get a failed login
to their local
>machine. The domain registers these logon failures I
suppose because the
>machine itself is a member of the domain. The really
weird thing is that
>the "logon type" shows as type 3, network. How can a
local account have a
>network logon to its own machine?
>
>More wierdness, wherever the local admin account of the
server has been
>changed, _that_ name shows up with the failed 529. The
domain name is
>_always_ the name of the local server, the AD domain is
not referenced even
>once in all 200 of the 529's.
>
>Something... is causing these failed local admin logins
to happen every
>night at 2AM on servers. I think that's why the domain
admin account is
>receiving a call to get locked out is; because the domain
is confusing the
>local admin accounts with the domain admin account, and
thinking that _it_
>is the culprit.
>
>The first thing we're going to do is rename the domain
admin account (yes I
>know I should have done this a long time ago, but there
are services,
>scheduled tasks, etc. running under that name that I have
to track down and
>remediate before I change it).
>
>The next thing I will do is I will check with our server
team about nightly
>processes/tasks that may be occurring at 2AM, but I
wonder if there is
>something in the undulations of AD itself that is
triggering this, such as a
>master browser election.
>
>If anyone can shed any light or has experienced something
similar, I am open
>to any advice you could give.
>
>Thanks a bunch!!
>
>
>.
>



Relevant Pages

  • Re: Howto refresh IIS 6 Application pool identity credential info
    ... The Application Servers are load balanced clustered, ... HostHeader names in IIS, it has a CNAME in DNS referencing ... Only account A has access to database DB-A ...
    (microsoft.public.inetserver.iis.security)
  • Re: Forest to Child -- Permissions
    ... My account can login to all the DCs and has full administrator priv. ... first DC in the root. ... the member servers only ... never happen unless some admin has been mucking about. ...
    (microsoft.public.windows.server.dns)
  • Re: Forest to Child -- Permissions
    ... My account can login to all the DCs and has full administrator priv. ... first DC in the root. ... the member servers only ... never happen unless some admin has been mucking about. ...
    (microsoft.public.windows.server.dns)
  • Re: Cant receive mail.
    ... Gary VanderMolen, MS-MVP (Mail) ... username being on the Servers tab. ... try to put in my wife's email address and it didn't authenticate. ... the only email account shown there is your wife's. ...
    (microsoft.public.windows.vista.mail)
  • Re: Cant receive mail.
    ... username being on the Servers tab. ... try to put in my wife's email address and it didn't authenticate. ... the only email account shown there is your wife's. ... I have Vista and Windows Mail on my laptop, with the account showing my emai ...
    (microsoft.public.windows.vista.mail)