Re: Administrator Password changes

Tech-Archive recommends: Fix windows errors by optimizing your registry



Hi
have a look
http://www.eventid.net/display.asp?eventid=642&eventno=226&source=Security&phase=1


--
I hope that the information above helps you.
Have a Nice day.

Jorge Silva
MCSE, MVP Directory Services
"Millette" <Millette@xxxxxxxxxxxxxxxxxxxxxxxxx> wrote in message
news:EC628285-E0C3-4B9D-B143-C5944EB6BDF1@xxxxxxxxxxxxxxxx
My network administrator password keeps getting altered somehow. The DC
does
not log any password change events. I do notice the following in the event
log.

Event Type: Success Audit
Event Source: Security
Event Category: Account Management
Event ID: 642
Date: 6/20/2007
Time: 11:10:33 AM
User: damin\mailserver$
Computer: DC
Description:
User Account Changed:
Target Account Name: Administrator
Target Domain: domain
Target Account ID: domain\administrator
Caller User Name: mailserver$
Caller Domain: domain
Caller Logon ID: (0x0,0x1652CD6)
Privileges: -
Changed Attributes:
Sam Account Name: -
Display Name: Administrator
User Principal Name: -
Home Directory: -
Home Drive: -
Script Path: -
Profile Path: -
User Workstations: -
Password Last Set: -
Account Expires: -
Primary Group ID: -
AllowedToDelegateTo: -
Old UAC Value: -
New UAC Value: -
User Account Control: -
User Parameters: -
Sid History: -
Logon Hours: -


For more information, see Help and Support Center at
http://go.microsoft.com/fwlink/events.asp.

--
Chris Millette
MCP/Network Administrator
Community Bank & Trust


.



Relevant Pages

  • Re: Account management audit
    ... if you add or remove a user account object from ... > Target Account ID: ICB\ralfeus ... > Caller Domain: ICB ...
    (microsoft.public.win2000.active_directory)
  • Re: Urgent: All AD users are locked out
    ... MCSE, MVP Directory Services ... Now I did an workaround by changing the account lockout threshold to 0 to ... "Jorge Silva" wrote: ... You need to identify where the locks are coming from and check on ...
    (microsoft.public.windows.server.active_directory)
  • Re: Account management audit
    ... Event Category: Account Management ... Target Domain: ICB ... Target Account ID: ICB\ralfeus ... Caller Domain: ICB ...
    (microsoft.public.win2000.active_directory)
  • Re: Log Information
    ... Description: User Account Deleted: ... Target Account ID: %3 Caller User Name: %4 ... Audit account managementhttp://www.microsoft.com/technet/prodtechnol/windows2000serv/reskit/g ... ...
    (microsoft.public.exchange.admin)
  • Re: Urgent: All AD users are locked out
    ... the auditing is turned on and all ws are for the inside. ... Now I did an workaround by changing the account lockout threshold to 0 to ... "Jorge Silva" wrote: ... MCSE, MVP Directory Services ...
    (microsoft.public.windows.server.active_directory)