Failure Audit

From: Bob (Bob_at_discussions.microsoft.com)
Date: 10/29/04

  • Next message: Bob: "RE: Failure Audit"
    Date: Fri, 29 Oct 2004 09:13:07 -0700
    
    

    Every ten minutes I get four hits in the DC security logs for the following:
    Event Type: Failure Audit
    Event Source: Security
    Event Category: Account Logon
    Event ID: 681
    Date: 10/29/2004
    Time: 10:53:41 AM
    User: NT AUTHORITY\SYSTEM
    Computer: MAS200
    Description:
    The logon to account: mooret
     by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0
     from workstation: TIM-MOBILE
     failed. The error code was: 3221225586
     
    The mooret account is disabled, and the primary user of the Tim-Mobile
    workstation used to be mooret before he left.
    There are no services on the machine trying to use that account and I have
    no idea what is running on that machine that is trying to logon to the DC.

    How can I track it down?

    Thanks, Bob


  • Next message: Bob: "RE: Failure Audit"

    Relevant Pages

    • Failure Audit
      ... The mooret account is disabled, and the primary user of the Tim-Mobile ... workstation used to be mooret before he left. ...
      (microsoft.public.win2000.security)
    • Failure Audit
      ... The mooret account has been disabled, but I have no idea what is running on ... the TIM-MOBILE workstation that is trying to logon to the DC. ...
      (microsoft.public.win2000.security)
    • Re: Trust relationship between this workstation and Primary Domain
      ... it, with a new computer ID, a new workgroup ID, but again to no avail. ... password policy, renamed admin account, automatic updates are controlled by ... * PLEASE post all messages and replies in the newsgroups ... "Workstation ...
      (microsoft.public.win2000.networking)
    • Re: Re-Post - "the trust relationship between this workstation and
      ... account is NEW to the workstation. ... needs admin group priv at workstation level. ... only problem is adding a new user account on the station. ... This would be on the DNS server 172.20.100.2 ...
      (microsoft.public.windows.server.active_directory)
    • Re: Re-Post - "the trust relationship between this workstation and
      ... "the trust relationship between this workstation and the primary domain ... only problem is adding a new user account on the station. ... The DNS Zone for your AD Domain must be DYNAMIC, ... Client computer must use STRICTLY the INTERNAL DNS server which can ...
      (microsoft.public.windows.server.active_directory)