Re: NETLOGON - 5722

From: Jerold Schulman (Jerry_at_jsiinc.com)
Date: 04/29/04


Date: Thu, 29 Apr 2004 14:28:52 -0400

On Thu, 29 Apr 2004 00:36:02 -0700, "Michael S. Androsov"
<anonymous@discussions.microsoft.com> wrote:

>On a domain controller Windows Server 2000 (SP4) in the Event Log I receving next message about single computer:
>Source: NETLOGON
>ID: 5722
>The session setup from the computer <computername> failed to authenticate. The name of the account referenced in the security database is <comutername>$. The following error occurred: Access is denied.
>
>What's a problem?
>
>Michael S. Androsov
>EXPOCENTR

See the following possibilities:

http://support.microsoft.com?kbid=154501 "How to disable automatic machine
account password changes"
http://support.microsoft.com?kbid=216393 "Resetting Computer Accounts in Windows
2000 and Windows XP"
http://support.microsoft.com?kbid=260575 "HOW TO Use Netdom.exe to Reset Machine
Account Passwords of a Windows 2000 Domain Controller"
http://support.microsoft.com?kbid=288167 "Error Message 'Target Principal Name
is Incorrect' When Manually Replicating Data Between Domain Controllers"
http://support.microsoft.com?kbid=322346 "You Cannot Access Protected Data After
You Change Your Password"
http://support.microsoft.com?kbid=324184 "Access Violation in Lsass.exe Because
of LDAP Version 2 Search with Referrals"
http://support.microsoft.com?kbid=324308 "Authenticated Users May Be Able to
Delete Sysvol Junctions on Windows 2000 Domain Controllers"
http://support.microsoft.com?kbid=325378 "Windows 2000-Based Domain Controller
Is Slow to Remove an Object in a Global Catalog"
http://support.microsoft.com?kbid=325641 "Cannot Connect in the Active Directory
Users and Computers Tool"
http://support.microsoft.com?kbid=327536 "'Stop 0x0000006b' or Setup Stops
Responding at 'Setup is Starting Windows' When You Install a Windows XP SP1
Client Image from a RIS Server"
http://support.microsoft.com?kbid=327709 "Windows 2000 Account Operators Can
Manage Their Own Accounts"
http://support.microsoft.com?kbid=327825 "New Resolution for Problems That Occur
When Users Belong to Many Groups"
http://support.microsoft.com?kbid=328570 "Existing Computers Are Not Updated to
the DNS-Style Domain Name After You Upgrade the Domain to Active Directory"
http://support.microsoft.com?kbid=329420 "The LookupAccountSid Function Returns
the Wrong Name After You Rename Accounts"
http://support.microsoft.com?kbid=330030 "Computer with Disjoined Namespace Is
Not Authenticated by Using 802.1x with a Radius Server in its Domain"
http://support.microsoft.com?kbid=330194 "Unnecessary Kerberos Packages Sent
from the Client"
http://support.microsoft.com?kbid=810076 "Updates to Restricted Groups ['Member
of'] Behavior of User-Defined Local Groups"
http://support.microsoft.com?kbid=821240 "Netlogon Event ID 5722 on a Trusted
Primary Domain Controller"

Jerold Schulman
Windows: General MVP
JSI, Inc.
http://www.jsiinc.com



Relevant Pages

  • Re: Accounts gettng locked out
    ... > I have a 2000 Domain Controller with mostly XP ... I have some accounts that get continually ... "Logon - Failure" auditing on all the Windows Domain Controllers, ... You may not want to enable auditing of "Logon - Success" since some Success ...
    (microsoft.public.win2000.security)
  • Re: Anyone taken the plunge with "Do not allow anonymous enumeration of SAM accounts and shares"?
    ... Our AD is largish - about 40,000 user accounts with a hub datacentre ... and 50 domain controller locations worldwide. ... All our domain controllers run Windows 2003 SP1, ... or trust relationships? ...
    (microsoft.public.windows.server.active_directory)
  • Anyone taken the plunge with "Do not allow anonymous enumeration of SAM accounts and shares"?
    ... Our AD is largish - about 40,000 user accounts with a hub datacentre ... and 50 domain controller locations worldwide. ... All our domain controllers run Windows 2003 SP1, ... or trust relationships? ...
    (microsoft.public.windows.server.active_directory)
  • Re: change domain admin password
    ... Just make sure that the account password is also changed on services if the account was use for that. ... Just as an info, since Windows 2000 there is nolonger a PDC/BDC concept, all DC's are the same, differences are the 5 FSMO roles and how they have to be set. ... controller and the others are secondary domain controller. ...
    (microsoft.public.windows.server.active_directory)
  • Re: Group Policy for specific users
    ... See www.dougknox.com, Win XP Utilities, Windows XP Security Console. ... > network or attached to a domain controller. ... etc) one of the accounts. ... Group policy does exactly what I need ...
    (microsoft.public.windowsxp.security_admin)