Re: Re-occuring Administrator User Account Lockout
- From: "Paul Bergson" <pbergson@xxxxxxxxxxxxxxxxx>
- Date: Tue, 27 Sep 2005 07:16:15 -0500
I guess I should have read down to the failure code. Right on it is this
machine. Nice work.
--
Paul Bergson MCT, MCSE, MCSA, CNE, CNA, CCA
This posting is provided "AS IS" with no warranties, and confers no rights.
"Mr P" <parris@xxxxxxxxxxxxxx> wrote in message
news:vqlgj1hs9etn2ba1tlkguhuavv10k757bi@xxxxxxxxxx
>
>
> Check the scheduler service with an AT command and see if any rogue
> jobs are listed.
>
> Mark
>
> On Mon, 26 Sep 2005 10:03:14 -0700, "vzrogers"
> <vzrogers@xxxxxxxxxxxxxxxxxxxxxxxxx> wrote:
>
>>
>>Every week at approximately the same time, I notice one of the accounts in
>>my Administrators group gets locked out. Checked the Sec logs and find
>>the
>>following entry:
>>
>>Event Type: Failure Audit
>>Event Source: Security
>>Event Category: Account Logon
>>Event ID: 676
>>Date: 9/26/2005
>>Time: 12:51:39 PM
>>User: NT AUTHORITY\SYSTEM
>>Computer: DC1
>>Description:
>>Authentication Ticket Request Failed:
>> User Name: admnstr
>> Supplied Realm Name: DOMAINA
>> Service Name: krbtgt/DOMAINA
>> Ticket Options: 0x40810010
>> Failure Code: 0x12
>> Client Address: 127.0.0.1
>>
>>
>>
>>How can I determine what is causing this and where its coming from?
>
.
- Prev by Date: Re: How to reduce Forest trust Traffic ?
- Next by Date: Re: Problems with DC & Client PCs suddenly cannot access any IE pa
- Previous by thread: Re: Re-occuring Administrator User Account Lockout
- Next by thread: Re: Re-occuring Administrator User Account Lockout
- Index(es):
Relevant Pages
|