Re: MSExchangeSA errors



Hello,

Please check if there are some Logon Failure auditing events in the security
log. The event you are looking for would be as shown below:
=============================================
Event Type: Failure Audit
Event Source: Security
Event Category: Logon/Logoff
Event ID: 534
User: NT AUTHORITY\SYSTEM
Description:
Logon Failure:
Reason: The user has not been granted the requested logon type at this
machine
Domain: <Domain name>
Logon Type: 3
Logon Process: NtLmSsp
Authentication Package: NTLM
Workstation Name: <Workstation name>
=============================================

If Logon/Logoff auditing is not turned on, do so by following the procedure
mentioned in the following KB Article:

257225 IPsec troubleshooting in Microsoft Windows 2000 Server :
http://support.microsoft.com/?id=257225

If you see many 534 events like the one above, it means the "Access this
computer from teh network" rights has been restricted to a few users/groups
in the Local Computer Policy or the Default Domain Policy. This right is one
among the rights listed under "Local policies" \ "User Rights Assignment".
Ensure that this right is assigned to Authenticated Users.

Regards
--
Nagendra Sitharamaiah
MCSE, CCNA, MCT, CISSP
Microsoft
Use of included script samples are subject to the terms specified at
http://www.microsoft.com/info/cpyright.htm
This posting is provided "AS IS" with no warranties, and confers no rights.
Please do not send email to this address, post a reply to this newsgroup.

"dm" <dmihalko@xxxxxxxxxxx> wrote in message
news:OQxfTPcRFHA.252@xxxxxxxxxxxxxxxxxxxxxxx
> Hi everyone. Im kinda getting frustrated with this. I am running exchange
> 2003 sp1 and getting the following errors:
>
> -Microsoft Exchange System Attendant failed to add the local computer as a
> member of the DS group object 'cn=Exchange Domain
> Servers,cn=Users,dc=componentone,dc=com'.
>
> Please stop all the Microsoft Exchange services, add the local computer
> into the group manually and restart all the services.
>
> -Microsoft Exchange System Attendant has detected that the local computer
> is not a member of group 'cn=Exchange Domain
> Servers,cn=Users,dc=componentone,dc=com'. System Attendant is going to add
> the local computer into the group.
>
> so after researching into it i have followed this article:
> http://support.microsoft.com/default.aspx?scid=kb;en-us;271335
>
>
> weird thing is... the error still comes back, no matter what i do.
> - I removed and re-added to the Exchange Domain Servers security group.
> - I restarted all exchange services.
> - I rebooted
> - I put it back into the original OU, restarted services.
> - I removed and re-added to the Exchange Domain Servers security group.
> - I rebooted
>
> did this many times, and i just cant get rid of the error. everything
> works fine, i just hate errors in my event logs.
>
> anyone have any ideas?


.



Relevant Pages

  • Re: MSExchangeSA errors
    ... Well of course there are logon failures on the exchange server, ... > Please check if there are some Logon Failure auditing events in the ... > in the Local Computer Policy or the Default Domain Policy. ...
    (microsoft.public.exchange.admin)
  • Re: Can not figure out why?
    ... I can not find any scheduled task running at administrator. ... this exchange server get security event 629 and 680 every second? ... Logon Failure: ... 2000 DCs and Two node A/P clustering exchange 2003 SP2) Did I break ...
    (microsoft.public.windows.server.active_directory)
  • Re: Unauthorized access to OWA if account set to change password on lo
    ... MCSE | M+, S+, MCTS, Security+ ... We recently upgraded from Exchange 2000 to Exchange 2003 SP2 ... Our OWA was previously configured to allow users to change their password. ... next logon", the following page is displayed when they access OWA "You are ...
    (microsoft.public.exchange.admin)
  • Re: Logon Error - Event ID 533
    ... The suggestion regarding security logs should not apply if the overwrite option has been selected and you have the default maximum of 512 kb. ... How to Set Log Size and Overwrite Options ... The user cannot logon and no Profile folder is made, ... screen whether with a domain account or a local account from the ...
    (microsoft.public.windowsxp.help_and_support)
  • Re: Help with Security Logs
    ... Security" means that the event was generated by the security ... Primary User is the user context that actually performed the access; ... Client User is the user on behalf of whom the file was accessed. ... The Logon ID fields for Primary User and Client User identify a unique logon ...
    (microsoft.public.security)

Loading