Re: Failure Audit Security Log Event ID 577

From: Roger Abell (mvpNOSpam_at_asu.edu)
Date: 10/04/03


Date: Fri, 3 Oct 2003 22:33:35 -0700

You could try profiling what processes are running
in the account process, perhaps with aid from tools
from www.sysinternals.com
Also, does this happen with a newly defined account ?

-- 
Roger Abell
Microsoft MVP (Windows Server System: Security)
MCSE (W2k3,W2k,Nt4)  MCDBA
"Jake" <j.lomax@mgn.co.uk> wrote in message
news:0cea01c389f0$9db88da0$a001280a@phx.gbl...
> Hi Roger,
> Privilege use failures are all that is being audited and
> only one event is recorded, eventID 577. An event is
> logged every thirty seconds when the user is logged on.
> The workststion can be idle, ie. screensaver up, and the
> same event is still logged.
> I have tried altering the local security 'Increase
> scheduling priority' policy to 'Authenticated Users' and
> also 'Not Defined'. This had no apparent effect.
>
>
> >-----Original Message-----
> >Onr solution is to ease back on the events you are
> auditing.
> >Assuming you put the ******* in there for privacy,
> >logging of this is controlled by the "Audit privlege use"
> >
> >However, your subject (only) indicates that you are
> >getting many failures, and _if_ one lessens this category
> >of auditing it is usually to only log failures (not
> successes).
> >So in your case you probably need to track down what the
> >******** account is doing when it gets denied.
> >The user right that the account is not being granted is
> the
> >one shown in local policy as "Increase scheduling
> priority"
> >You may find that profiling the actions of the account
> will
> >lead you to a solution, for example KB 811196 is a case
> >where admin accounts trigger this event even though they
> >are granted the user right.
> >
> >-- 
> >Roger Abell
> >Microsoft MVP (Windows Server System: Security)
> >MCSE (W2k3,W2k,Nt4)  MCDBA
> >"Jake" <j.lomax@mgn.co.uk> wrote in message
> >news:08a601c38917$9ec10990$a301280a@phx.gbl...
> >> Does anyone know how to stop this failure audit event
> >> being recorded. Its happening on a couple of my clients
> >> now and with enforced 90 day log retention I need to
> keep
> >> increasing the log size, I'm not happy with this and
> want
> >> to know how to stop it.
> >>
> >> Privileged Service Called:
> >>   Server: Security
> >>   Service: -
> >>   Primary User Name: ********
> >>   Primary Domain: *******
> >>   Primary Logon ID: (0x0,0x****)
> >>   Client User Name: -
> >>   Client Domain: -
> >>   Client Logon ID: -
> >>   Privileges: SeIncreaseBasePriorityPrivilege
> >>
> >
> >
> >.
> >


Relevant Pages

  • RE: Event ID 529 on cleint workstation
    ... Security Event ID 529 is a failure audit for logon/logoff. ... "logon events" generate the events on domain controllers for domain account ... The Event 529 was caused by the machine account password not being ... I suggest that you re-join the client to ...
    (microsoft.public.windows.server.sbs)
  • Re: what is reset account?
    ... In general this applies to users who are admins or power users but if someone ever got access to control the settings for a service or the ability to modify the info for a service then it is possible to escalate to the proper security context. ... One of those occasions happened to me when I applied the GPO team's updates to the production domain and the ACL got wiped in the process thereby clearing the Group requirement which protected the GPO and thousands of workstations and servers around the world locked down to kiosk mode. ... I used that once as a stepping stone when doing a security check for a company several years ago and within an hour had escalated myself all the way up to EA and sent an email from the Chief of Security's mail account. ... If the client isn't talking or the person involved has insufficient access at the client or the client is offline the reset will only update the following attributes in AD ...
    (microsoft.public.win2000.active_directory)
  • Re: what is reset account?
    ... Security Settings | Local Policies | Security Options | Domain Member:Maximum machine account password age. ... deployed based on computer account. ... One of those occasions happened to me when I applied the GPO team's updates to the production domain and the ACL got wiped in the process thereby clearing the Group requirement which protected the GPO and thousands of workstations and servers around the world locked down to kiosk mode. ... If the client isn't talking or the person involved has insufficient access at the client or the client is offline the reset will only update the following attributes in AD ...
    (microsoft.public.win2000.active_directory)
  • RE: configuring client users
    ... This newsgroup only focuses on SBS technical issues. ... | Thread-Topic: configuring client users ... |> computer to SBS server while we need use "set up computer wizard" to ... |> For user account issue, please understand that if you join the client ...
    (microsoft.public.windows.server.sbs)
  • RE: configuring client users
    ... > Welcome to SBS newsgroup. ... we use "connect computer wizard" to connect the client ... > computer to SBS server while we need use "set up computer wizard" to set up ... > best interest to rerun the wizard again to add the client computer account ...
    (microsoft.public.windows.server.sbs)