Re: AT command and Access Denied

From: Steven L Umbach (n9rou_at_n0-spam-for-me-comcast.net)
Date: 10/29/04


Date: Fri, 29 Oct 2004 02:44:46 GMT

I don't think that event is related unless it is generated at the same time
that you tried to run the AT command, though be default administrators have
that user right. To see the explanation of that user right see the link
below.

http://www.microsoft.com/resources/documentation/WindowsServ/2003/standard/proddocs/en-us/Default.asp?url=/resources/documentation/WindowsServ/2003/standard/proddocs/en-us/542.asp

http://tinyurl.com/4hnn7 -- same link, shorter

The only other thing I can think of is to go to Control Panel, open
Scheduled Tasks and in go to advanced - view log to see if anything is
recorded there as to what the problem could be. There are free tools like
filemon and regmon from SysInternals that may help if you run them just
before you try to use the AT command, stop them as soon as the AT command
fails, and then look in the log of the program to see if you can find any
access denied messages for files or registry. The problem though is that
would be very hard to do on a busy server unless you can take it off the
network for a bit as regmon and filemon can generate thousands of entries in
their logs in half a minute. -- Steve

"aserret" <aserret@discussions.microsoft.com> wrote in message
news:91714C64-6349-475B-9B1D-AB5973991183@microsoft.com...
> I've checked the task scheduler and it is set to default all the other
> settings are also okay. Even if I log in as the local Admin I get the
> access
> denied error. this is only happening to a handful of servers (4 or 5 out
> of
> 53) I'm jsut worried now that I may have some sort of virus or something.
> All servers are created from the same image and they all have citrix and
> they
> all boot from M:. I turned on auditing for privilege use and this is the
> only error that comes up.
> Event Type: Failure Audit
> Event Source: Security
> Event Category: Privilege Use
> Event ID: 578
> Date: 10/28/2004
> Time: 7:12:43 AM
> User: IAC_NT\xASerret
> Computer: GCMF02
> Description:
> Privileged object operation:
> Object Server: Security
> Object Handle: 4294967295
> Process ID: 3492
> Primary User Name: GCMF02$
> Primary Domain: IAC_NT
> Primary Logon ID: (0x0,0x3E7)
> Client User Name: xaserret
> Client Domain: IAC_NT
> Client Logon ID: (0x0,0x414444)
> Privileges: SeIncreaseBasePriorityPrivilege
>
>
> "Steven L Umbach" wrote:
>
>> First double check that you are logged on as an account that is a local
>> administrator as shown by membership on the local administrators group.
>> If
>> you are logged on as a domain admin it is possible that group has been
>> removed from the local administrators group. Then check the logs in Event
>> Viewer to see if any pertinent errors are recorded. You may also want to
>> enable auditing of logon events for success and failure and privilege use
>> for failure which may generate some helpful info. That can be done in the
>> Local Security Policy of the server via secpol.msc. The other thing to
>> check
>> is to see if the Task Scheduler service is started and that it is
>> configured
>> to logon via the local system account and allow service to interact with
>> desktop is selected which is the default setting. --- Steve
>>
>>
>> "aserret" <aserret@discussions.microsoft.com> wrote in message
>> news:59D5B251-0ABB-4139-9289-3B03EB2C58F5@microsoft.com...
>> > Hi,
>> > I have used the AT command fairly extensively since the NT4 days but I
>> > can't
>> > seem to figure this out. Normally I will issue a command from my
>> > workstation
>> > such as
>> > c:\>at \\severname
>> > and I can get a list of task if any. however this one particular
>> > server I
>> > immediately receive Access Denied and if I logon locally and just type
>> > c:\>at
>> > I still get access denied.
>> > Any ideas?
>> >
>>
>>
>>



Relevant Pages

  • Re: file sharing only works for some files, not all
    ... If you now open another Command Prompt and type this ... Local Group Memberships *Administrators *Debugger Users ... Check your NTFS permissions, check your ...
    (microsoft.public.windowsxp.general)
  • Re: passwords Service accounts and services
    ... In these cases we had gone from all users being local administrators to ... Microsoft MVP - Windows Security ... process of applying the policy of "least privilege" trial and error at ... I hope these service accounts do not have excessive permissions ...
    (microsoft.public.windows.server.security)
  • Re: "Domain not found on this computer"
    ... Hi John. ... "reset" the administrators password to be able to logon and go from there. ... > permissions to Everyone and then applying them. ...
    (microsoft.public.win2000.security)
  • Re: Local Logon To Domain Controller
    ... That dose this administrators out to PCs have to do? ... PC Admins or what ever you want. ... >>> Server machine itself. ... >>logon locally on DCs. ...
    (microsoft.public.win2000.active_directory)
  • Re: Help with Guest account
    ... Are you sure you are using an administrator account and did you verify it ... You can also run the command net user ... it is a member of the administrators group under local group memberships. ... Local Group Memberships *Administrators *Network Configuration ...
    (microsoft.public.windowsxp.security_admin)