MSDTC Security Log Failure Audits

From: Andrew Phillips (APhillips_at_bigpond.net.au)
Date: 10/29/05


Date: Sat, 29 Oct 2005 18:41:10 +1000

While scrolling through the Security logs of a Windows 2003 box, I noticed
seven seperate security failure audit's from the MSDTC service relating to
accessing and writing to two MSDTC Logs.

The Audit's:

Audit 1:
Event Type: Failure Audit
Event Source: Security
Event Category: Object Access
Event ID: 560
Date: 29/10/2005
Time: 6:05:01 PM
User: NT AUTHORITY\NETWORK SERVICE
Computer: LFN-SVR-1
Description:
Object Open:
  Object Server: Security
  Object Type: File
  Object Name: C:\WINDOWS\system32\MsDtc\Trace\dtctrace.log
  Handle ID: -
  Operation ID: {0,51323}
  Process ID: 1372
  Image File Name: C:\WINDOWS\system32\msdtc.exe
  Primary User Name: NETWORK SERVICE
  Primary Domain: NT AUTHORITY
  Primary Logon ID: (0x0,0x3E4)
  Client User Name: -
  Client Domain: -
  Client Logon ID: -
  Accesses: DELETE
   SYNCHRONIZE
   ReadAttributes
  Privileges: -
  Restricted Sid Count: 0
  Access Mask: 0x110080

Audit 2:
Event Type: Failure Audit
Event Source: Security
Event Category: Object Access
Event ID: 560
Date: 29/10/2005
Time: 6:05:01 PM
User: NT AUTHORITY\NETWORK SERVICE
Computer: LFN-SVR-1
Description:
Object Open:
  Object Server: Security
  Object Type: File
  Object Name: C:\WINDOWS\system32\MsDtc\Trace\dtctrace.log
  Handle ID: -
  Operation ID: {0,51326}
  Process ID: 1372
  Image File Name: C:\WINDOWS\system32\msdtc.exe
  Primary User Name: NETWORK SERVICE
  Primary Domain: NT AUTHORITY
  Primary Logon ID: (0x0,0x3E4)
  Client User Name: -
  Client Domain: -
  Client Logon ID: -
  Accesses: DELETE
   SYNCHRONIZE
   ReadAttributes
  Privileges: -
  Restricted Sid Count: 0
  Access Mask: 0x110080

Audit 3:
Event Type: Failure Audit
Event Source: Security
Event Category: Object Access
Event ID: 560
Date: 29/10/2005
Time: 6:05:01 PM
User: NT AUTHORITY\NETWORK SERVICE
Computer: LFN-SVR-1
Description:
Object Open:
  Object Server: Security
  Object Type: File
  Object Name: C:\WINDOWS\system32\MsDtc\Trace\dtctrace.log
  Handle ID: -
  Operation ID: {0,51347}
  Process ID: 1372
  Image File Name: C:\WINDOWS\system32\msdtc.exe
  Primary User Name: NETWORK SERVICE
  Primary Domain: NT AUTHORITY
  Primary Logon ID: (0x0,0x3E4)
  Client User Name: -
  Client Domain: -
  Client Logon ID: -
  Accesses: DELETE
   ReadAttributes
  Privileges: -
  Restricted Sid Count: 0
  Access Mask: 0x10080

Audit 4:
Event Type: Failure Audit
Event Source: Security
Event Category: Object Access
Event ID: 560
Date: 29/10/2005
Time: 6:05:01 PM
User: NT AUTHORITY\NETWORK SERVICE
Computer: LFN-SVR-1
Description:
Object Open:
  Object Server: Security
  Object Type: File
  Object Name: C:\WINDOWS\system32\MsDtc\Trace\dtctrace.log
  Handle ID: -
  Operation ID: {0,51350}
  Process ID: 1372
  Image File Name: C:\WINDOWS\system32\msdtc.exe
  Primary User Name: NETWORK SERVICE
  Primary Domain: NT AUTHORITY
  Primary Logon ID: (0x0,0x3E4)
  Client User Name: -
  Client Domain: -
  Client Logon ID: -
  Accesses: DELETE
  Privileges: -
  Restricted Sid Count: 0
  Access Mask: 0x10000

Audit 5:
Event Type: Failure Audit
Event Source: Security
Event Category: Object Access
Event ID: 560
Date: 29/10/2005
Time: 6:05:01 PM
User: NT AUTHORITY\NETWORK SERVICE
Computer: LFN-SVR-1
Description:
Object Open:
  Object Server: Security
  Object Type: File
  Object Name: C:\WINDOWS\DtcInstall.log
  Handle ID: -
  Operation ID: {0,51454}
  Process ID: 1372
  Image File Name: C:\WINDOWS\system32\msdtc.exe
  Primary User Name: NETWORK SERVICE
  Primary Domain: NT AUTHORITY
  Primary Logon ID: (0x0,0x3E4)
  Client User Name: -
  Client Domain: -
  Client Logon ID: -
  Accesses: READ_CONTROL
   SYNCHRONIZE
   ReadData (or ListDirectory)
   WriteData (or AddFile)
   AppendData (or AddSubdirectory or CreatePipeInstance)
   ReadEA
   WriteEA
   ReadAttributes
   WriteAttributes
  Privileges: -
  Restricted Sid Count: 0
  Access Mask: 0x12019F

Audit 6:
Event Type: Failure Audit
Event Source: Security
Event Category: Object Access
Event ID: 560
Date: 29/10/2005
Time: 6:05:01 PM
User: NT AUTHORITY\NETWORK SERVICE
Computer: LFN-SVR-1
Description:
Object Open:
  Object Server: Security
  Object Type: File
  Object Name: C:\WINDOWS\DtcInstall.log
  Handle ID: -
  Operation ID: {0,51458}
  Process ID: 1372
  Image File Name: C:\WINDOWS\system32\msdtc.exe
  Primary User Name: NETWORK SERVICE
  Primary Domain: NT AUTHORITY
  Primary Logon ID: (0x0,0x3E4)
  Client User Name: -
  Client Domain: -
  Client Logon ID: -
  Accesses: READ_CONTROL
   SYNCHRONIZE
   ReadData (or ListDirectory)
   WriteData (or AddFile)
   AppendData (or AddSubdirectory or CreatePipeInstance)
   ReadEA
   WriteEA
   ReadAttributes
   WriteAttributes
  Privileges: -
  Restricted Sid Count: 0
  Access Mask: 0x12019F

Audit 7:
Event Type: Failure Audit
Event Source: Security
Event Category: Object Access
Event ID: 560
Date: 29/10/2005
Time: 6:05:02 PM
User: NT AUTHORITY\NETWORK SERVICE
Computer: LFN-SVR-1
Description:
Object Open:
  Object Server: Security
  Object Type: File
  Object Name: C:\WINDOWS\DtcInstall.log
  Handle ID: -
  Operation ID: {0,51767}
  Process ID: 1372
  Image File Name: C:\WINDOWS\system32\msdtc.exe
  Primary User Name: NETWORK SERVICE
  Primary Domain: NT AUTHORITY
  Primary Logon ID: (0x0,0x3E4)
  Client User Name: -
  Client Domain: -
  Client Logon ID: -
  Accesses: READ_CONTROL
   SYNCHRONIZE
   ReadData (or ListDirectory)
   WriteData (or AddFile)
   AppendData (or AddSubdirectory or CreatePipeInstance)
   ReadEA
   WriteEA
   ReadAttributes
   WriteAttributes
  Privileges: -
  Restricted Sid Count: 0
  Access Mask: 0x12019F

My interpretation of these audit's is that the MSDTC service is trying to
modify it's log files and failing, due to incorrect permissions. However,
both files have full access given to the NETWORK SERVICE account. Can anyone
provide any suggestions on how to fix this permissions issue and remove
these failure audits? Thanks...



Relevant Pages

  • Re: Services Security Failure Audit
    ... > Primary Logon ID: ... > Client User Name: NETWORK SERVICE ... > A quick bit of experimentation revealed that this Failure Audit occurs ... relatively early in the Windows boot-up process. ...
    (microsoft.public.windows.server.security)
  • Re: Ntbackup Windows 2003 SP1 issue (VSS/Security)
    ... the Users group on the machine where the access is throwing ... Microsoft MVP (Windows Security) ... > Primary Logon ID: ... > Client Domain: VLM ...
    (microsoft.public.windows.server.security)
  • WwK3 cluster + MSSQL sp3a upg.
    ... the setup for MS SQL sp3a it stops saying that it cannot detect the satus of ... We have applied a security template which might conflict with MS ... Primary Logon ID: ... Client User Name: NETWORK SERVICE ...
    (microsoft.public.sqlserver.clustering)
  • Re: 560 errors
    ... security policy. ... > Event Type: Failure Audit ... > Primary Logon ID: ... > Client User Name: - ...
    (microsoft.public.win2000.security)
  • Re: Why does this keep happening...
    ... here's what's showing up in my security log in the event ... Object Server: Security ... Primary Logon ID: ... Client User Name: - ...
    (microsoft.public.inetserver.iis.security)