Re: Authentication Failure

From: Sam Spade (sams_at_not.real.actually.fake)
Date: 09/08/05

  • Next message: Sam Spade: "Re: Authentification Blocked in Safemode start (W2000 Pro)"
    Date: Thu, 08 Sep 2005 02:32:32 -0700
    
    

    Hi Steven,

    We're on the same wavelength - I'd already saved and cleared the logs.
    There is nothing showing in the event logs on the DC. I'm really
    confused! I'm going to re-image the two affected machines today (yes, a
    4th one has gone now!) then I'll turn on MORE auditing to see if I can
    discover what's causing this VERY annoying problem!

    Thanks for the advice so far....

    Sam.

    "Steven L Umbach" <n9rou@nospam-comcast.net> wrote in
    news:OKm1$H8sFHA.908@tk2msftngp13.phx.gbl:

    > This may be a longshot but next time try logging on as a local
    > administrator and clearing the security log. The reason being if you
    > have crashonauditfail security option enabled in the security policy
    > it could prevent any user other than a local administrator from
    > logging onto the computer when the security log becomes full but
    > usually the computer blue screens when this is enabled and the
    > security log becomes full. Also look in the security logs of your
    > domain controllers to see if any failed logon events are recorded for
    > those domain users that may provide more information. You would want
    > to make sure that auditing of "account logon" events and account
    > management are enabled in Domain Controller Security Policy and that
    > the security logs have been increased in size from default quite a bit
    > to say at least 20MB. --- Steve
    >
    >
    > "Sam Spade" <sams@not.real.actually.fake> wrote in message
    > news:Xns96CA9DF3C35F7Samisnotactuallyreal@207.46.248.16...
    >> Steven,
    >>
    >> Thanks for the reply. Netdiag shows no problems except no default
    >> gateway is defined - not a problem as all Internet traffic is forced
    >> through the ISA Server.
    >>
    >> I can log onto the affected workstations as Local Administrator _OR_
    >> as Domain administrator. As Domain Admin. I have full connectivity.
    >>
    >> I am perplexed. Any other suggestions?
    >>
    >> Sam.
    >>
    >>
    >> "Steven L Umbach" <n9rou@nospam-comcast.net> wrote in
    >> news:#j8kGQ2sFHA.3088@TK2MSFTNGP12.phx.gbl:
    >>
    >>> Next time that happens see if a local administrator can logon to the
    >>> computer and then run the support tool netdiag on it to see if it
    >>> reports any problems with dns, dc discovery, kerberos, secure
    >>> channel/computer account, etc. Make sure your domain computers
    >>> point only to domain controllers as their preferred dns servers.
    >>> --- Steve
    >>>
    >>>
    >>> "Sam Spade" <sams@not.real.actually.fake> wrote in message
    >>> news:Xns96C97390F2B18Samisnotactuallyreal@207.46.248.16...
    >>>> Group,
    >>>>
    >>>> Bit of a weird one here....
    >>>>
    >>>> I have set up an entirely Win2K network and locked the permissions
    >>>> down hard.
    >>>>
    >>>> Occasionally, and this has now happened on three of the
    >>>> workstations, when a user tries to logon we get:
    >>>>
    >>>> security event 533
    >>>> Reason: User not allowed to logon at this computer
    >>>> Logon process User32
    >>>>
    >>>> Nothing has changed on the users permissions or group policy, they
    >>>> are all domain users and can log on to any other workstations.
    >>>>
    >>>> I have cured this in the past my re-imaging the drive - a fairly
    >>>> simple process but I'd actually like to know what is going wrong.
    >>>>
    >>>> Any ideas anyone?
    >>>>
    >>>> TIA,
    >>>>
    >>>> Sam.
    >>>
    >>>
    >>>
    >>
    >
    >


  • Next message: Sam Spade: "Re: Authentification Blocked in Safemode start (W2000 Pro)"

    Relevant Pages

    • Accessing eventlogs remotely on W2K3 Server
      ... (minus the security log). ... This is easy to do in W2K server by having them use the run as command ... must be a local admin on the server to view event logs remotely. ...
      (Focus-Microsoft)
    • Re: Reading Security Event Logs with Service Account
      ... the right pane will be Manage auditing and security log. ... then set that in the GPO for the OU where the servers are. ... Add the user account to that group afterwards. ... logs on Windows servers. ...
      (microsoft.public.windows.server.security)
    • Re: System Logging on Windows
      ... clearing of event logs domain wide to some dedicated box of your choosing. ... >>logs of the domain clients to be logged in the security log of the ... > - Precisely Define and Implement Network Security ... > FIND OUT NOW - FREE Vulnerability Assessment Toolkit ...
      (Security-Basics)
    • Re: Hiding Source Network Address
      ... the security log if auditing of logon events is enabled. ... security logs with the firewall logs to find the information that you need. ... The Windows ...
      (microsoft.public.windows.server.security)
    • Re: anonymous access to security/application/system logs
      ... authenticated users can access the logs locally but not ... remotely on w2k3 servers. ... the security log can only be accessed by admins, ...
      (microsoft.public.windows.server.active_directory)