Re: Events 673, 675, 566

Tech Tip: Click here to run a free scan for Windows Errors and optimize PC performance



Since this is kerberos, is the time on the client within 5 minutes of the
dc?

Also is this a 2000 machine in a 2003 Domain? It could also be a 2003
machine misconfigured in a 2003 domain.

See:
http://support.microsoft.com/kb/824905/en-us

--


Paul Bergson MCT, MCSE, MCSA, CNE, CNA, CCA

This posting is provided "AS IS" with no warranties, and confers no rights.


"musicman" <ryantracy@xxxxxxxxxxxx> wrote in message
news:1139265762.455785.71060@xxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx
Hello All,
I'm seeing multiple instances of the following events with alarming
frequency - any ideas?

Event Type: Failure Audit
Event Source: Security
Event Category: Account Logon
Event ID: 673
Date: 2/6/2006
Time: 2:52:28 PM
User: NT AUTHORITY\SYSTEM
Computer: MYDCDC1
Description:
Service Ticket Request:
User Name:
User Domain: HQ.COMPANY.COM
Service Name: host/servername.hq.company.com
Service ID: -
Ticket Options: 0x40830000
Ticket Encryption Type: -
Client Address: 10.1.2.96
Failure Code: 0xD
Logon GUID: -
Transited Services: -


For more information, see Help and Support Center at
http://go.microsoft.com/fwlink/events.asp.




Event Type: Failure Audit
Event Source: Security
Event Category: Account Logon
Event ID: 675
Date: 2/6/2006
Time: 2:54:25 PM
User: NT AUTHORITY\SYSTEM
Computer: MYDC2
Description:
Pre-authentication failed:
User Name: username
User ID: mydomain\username
Service Name: krbtgt/cso
Pre-Authentication Type: 0x2
Failure Code: 0x18
Client Address: 10.1.2.172


For more information, see Help and Support Center at
http://go.microsoft.com/fwlink/events.asp.


Event Type: Failure Audit
Event Source: Security
Event Category: Directory Service Access
Event ID: 566
Date: 2/6/2006
Time: 2:53:03 PM
User: ENG\RtcService
Computer: MYDC2
Description:
Object Operation:
Object Server: DS
Operation Type: Object Access
Object Type: domainDNS
Object Name: DC=hq,DC=company,DC=com
Handle ID: -
Primary User Name: MYDC2$
Primary Domain: CSO
Primary Logon ID: (0x0,0x3E7)
Client User Name: RtcService
Client Domain: ENG
Client Logon ID: (0x0,0x40935FF)
Accesses: Control Access

Properties:
---
Replicating Directory Changes
domainDNS

Additional Info:
Additional Info2:
Access Mask: 0x100


For more information, see Help and Support Center at
http://go.microsoft.com/fwlink/events.asp.



.



Relevant Pages

  • Re: Cant access desktop of client pc
    ... Event Source: NETLOGON ... Log onto a problematic client computer. ... Logon to the problematic client as a user who can logon to other ... not supported in newsgroup support. ...
    (microsoft.public.windows.server.sbs)
  • RE: Event ID 529 on cleint workstation
    ... Security Event ID 529 is a failure audit for logon/logoff. ... "logon events" generate the events on domain controllers for domain account ... The Event 529 was caused by the machine account password not being ... I suggest that you re-join the client to ...
    (microsoft.public.windows.server.sbs)
  • Re: Event ID 529 on cleint workstation
    ... "logon events" generate the events on domain controllers for domain account ... The Event 529 was caused by the machine account password not being ... I suggest that you re-join the client to ... Microsoft CSS Online Newsgroup Support ...
    (microsoft.public.windows.server.sbs)
  • Re: NT4 -> Win2K3 question
    ... "not allow me logon to domain." ... I suspect you still unable to join the ... client into domain, right? ... Get Secure! ...
    (microsoft.public.windows.server.migration)
  • Re: windows client cant start completely...get blank desktop and no icons, start button, task bar, e
    ... Can you access the registry remotely from another workstation or the ... "Logon to the problematic client as a user who can logon to other ... Logon to a working client as the user who encountered the problem. ... not supported in newsgroup support. ...
    (microsoft.public.windows.server.sbs)