Re: Windows 2000 Login problems

Tech Tip: Click here to run a free scan for Windows Errors and optimize PC performance

From: Dave Patrick (mail_at_Nospam.DSPatrick.com)
Date: 01/13/05


Date: Thu, 13 Jan 2005 09:31:03 -0700

Is this a server or workstation? Can you connect to any network resources
using those domain credentials from this machine? Any system log errors?

-- 
Regards,
Dave Patrick ....Please no email replies - reply in newsgroup.
Microsoft Certified Professional
Microsoft MVP [Windows]
http://www.microsoft.com/protect
"Phil" wrote:
| You get 4 entries
|
| Event Type: Success Audit
| Event Source: Security
| Event Category: Logon/Logoff
| Event ID: 538
| Date: 1/13/2005
| Time: 9:26:01 AM
| User: DOMAINNAME\PhilTest
| Computer: SERVERNAME
| Description:
| User Logoff:
|  User Name: PhilTest
|  Domain: DOMAINNAME
|  Logon ID: (0x0,0xB24E95)
|  Logon Type: 2
|
|
| Event Type: Success Audit
| Event Source: Security
| Event Category: Detailed Tracking
| Event ID: 593
| Date: 1/13/2005
| Time: 9:23:50 AM
| User: DOMAINNAME\PhilTest
| Computer: SERVERNAME
| Description:
| A process has exited:
|  Process ID: 4416
|  User Name: PhilTest
|  Domain: DOMAINNAME
|  Logon ID: (0x0,0xB5D5B1)
|
|
| Event Type: Success Audit
| Event Source: Security
| Event Category: Logon/Logoff
| Event ID: 528
| Date: 1/13/2005
| Time: 9:23:48 AM
| User: DOMAINNAME\PhilTest
| Computer: SERVERNAME
| Description:
| Successful Logon:
|  User Name: PhilTest
|  Domain: DOMAINNAME
|  Logon ID: (0x0,0xB5D5B1)
|  Logon Type: 2
|  Logon Process: User32
|  Authentication Package: Negotiate
|  Workstation Name: SERVERNAME
|
| Event Type: Success Audit
| Event Source: Security
| Event Category: Privilege Use
| Event ID: 576
| Date: 1/13/2005
| Time: 9:23:48 AM
| User: DOMAINNAME\PhilTest
| Computer: SERVERNAME
| Description:
| Special privileges assigned to new logon:
|  User Name: PhilTest
|  Domain: DOMAINNAME
|  Logon ID: (0x0,0xB5D5B1)
|  Assigned: SeChangeNotifyPrivilege
| SeBackupPrivilege
| SeRestorePrivilege
| SeDebugPrivilege
|
|
| "Dave Patrick" wrote:
|
| > Anything logged in Event Viewer?
| >
| > -- 
| > Regards,
| >
| > Dave Patrick ....Please no email replies - reply in newsgroup.
| > Microsoft Certified Professional
| > Microsoft MVP [Windows]
| > http://www.microsoft.com/protect
| >
| > "Phil" wrote:
| > | Same thing local accounts are ok but domain accounts are logged off.
| > | should also say this is a member server in a NT4 domain.
| >
| >
| > 


Relevant Pages

  • Many Logon/Logoff Entries
    ... Event Type: Success Audit ... Event Source: Security ... Logon ID: ...
    (microsoft.public.windows.server.sbs)
  • Re: Whats this?
    ... "siljaline" wrote in message ... > Event Type: Success Audit ... > Successful Logon: ...
    (microsoft.public.security)
  • Event Log - Security - Numerous Failures
    ... Event Type: Failure Audit ... Computer: <servername> ... The logon to account: Administrator ...
    (microsoft.public.windows.server.security)
  • Re: 540,576,538
    ... I disable the local user and I get an failure to logon now. ... Event Type: Success Audit ... Caller User Name: - ...
    (microsoft.public.security)
  • Re: anonymous logon
    ... I see many of these 'Event Type: ... Success Audit' on the network at work also and I'm sure I'm not being ... > Successful Network Logon: ...
    (microsoft.public.windowsxp.general)