Re: Event ID: 673 - Failure Audit

From: MikeH (MikeH_at_discussions.microsoft.com)
Date: 05/24/05


Date: Tue, 24 May 2005 02:41:02 -0700

Ben, something else to review.

In my situation, I am doing complete auditing.

I have a service account (_ServiceAccount) that connects to a DC and then
passes the credentials of a user account to log that user in.

I first see the Kerberos error w/hex 0x19 indicated.
Then I see the failure audit for the 0x4081000 Service Ticket request, and
this is on the _ServiceAccount
Immediately following I see a Service Ticket Request that is successful for
the same _ServiceAccount

You may want to check and see if this is happening in your case. It's very
possible that a first attempt for the service ticket failed, and if you're
auditing failures (obviously you must be) you'll see EVERY failure - and
could miss the forrest for the trees (sorry for the pun). Your service
account may be working fine.
"Ben" wrote:

> Community Message Not Available



Relevant Pages

  • Re: Is it really true that NTFS is secure?
    ... > and failure auditing starting with "Audit Account Management," and also try ... > The account Group got put back in the Administrator group again. ... > The logon to account: ...
    (microsoft.public.security)
  • Re: Is it really true that NTFS is secure?
    ... and failure auditing starting with "Audit Account Management," and also try ... The account Group got put back in the Administrator group again. ... The logon to account: Administrator ...
    (microsoft.public.security)
  • Re: Account Lockout
    ... Enable auditing and look for lockout ... From the lockout events, determine which clients they originate from. ... >>> Do this via a GPO and watch for failed logon attempts. ... I have a user's account that is getting ...
    (microsoft.public.win2000.active_directory)
  • Re: Computers lose domain trust
    ... Search for Event id 647 Computer account deleted ... "Meinolf Weber" wrote: ... Audit account logon events success, failure ...
    (microsoft.public.windows.server.active_directory)
  • Re: Account Lockout
    ... Enable auditing and look for lockout events. ... >> Do this via a GPO and watch for failed logon attempts. ... I have a user's account that is getting ...
    (microsoft.public.win2000.active_directory)