Re: Security Event ID 533 - user can't access OWA or RWW



How about if I allow logon to the server, but restrict the other computers she can logon to?

"SteveB" <newsgroup@xxxxxxxxxx> wrote in message news:elWxcpvhJHA.1252@xxxxxxxxxxxxxxxxxxxxxxx
I don't think you can restrict the login to the SBS since you're logging in and authenticating there for OWA and RWW.

"Mike in Nebraska" <Mike_in_Nebraska@xxxxxxxxxxxxxxxx> wrote in message news:9A6CE2CE-9ABA-4184-9296-EF721234EB37@xxxxxxxxxxxxxxxx
Yes, she is.

Yes, her computer and one other (not the server).
"Cris Hanna [SBS - MVP]" <crisnospamhanna@xxxxxxxxxxxxxxxxxxxxx> wrote in message news:eW8I9quhJHA.4408@xxxxxxxxxxxxxxxxxxxxxxx
Is the user a member of the Remote Web Workplace security group?

Have you set up ADUC to limit which computers can be logged on to?

--
Cris Hanna [SBS - MVP]
Co-Author, Windows Small Business Server 2008 Unleashed
http://www.amazon.com/Windows-Small-Business-Server-Unleashed/dp/0672329573/ref=pd_bbs_sr_1?ie=UTF8&s=books&qid=1217269967&sr=8-1
Owner, CPU Services, Belleville, IL
A Microsoft Registered Partner
------------------------------------
MVPs do not work for Microsoft
Please do not submit questions directly to me.

"Mike in Nebraska" <Mike_in_Nebraska@xxxxxxxxxxxxxxxx> wrote in message news:480972A3-7841-414D-A65B-8B3F7A4D0FCA@xxxxxxxxxxxxxxxx
SBS 2003 Premium, current with patches and updates. User running Vista
Business.
=================
New employee, setup in SBS with Add User Wizard. Unable to login to OWA or
RWW either internally or externally - also tried on other computers.
Checked her account in ADUC and found nothing wrong compared to other users.
Keep getting this error in server security log:

Event Type: Failure Audit
Event Source: Security
Event Category: Logon/Logoff
Event ID: 533
Date: 1/30/2009
Time: 6:30:57 AM
User: NT AUTHORITY\SYSTEM
Computer: <computername>
Description:
Logon Failure:
Reason: User not allowed to logon at this computer
User Name: jessica
Domain: <computername>
Logon Type: 3
Logon Process: Advapi
Authentication Package: Negotiate
Workstation Name: <computername>
Caller User Name: IUSR_<computername>
Caller Domain: <domainname>
Caller Logon ID: (0x0,0x3B5E3)
Caller Process ID: 6008 <this is w3wp.exe, called by user NETWORK
SERVICE>
Transited Services: -
Source Network Address: -
Source Port: -

I've tried (twice) backing up her email and docs, then deleting her account
(rebooted server the second time), before adding her back in -- same result.
I can create a new account with a different name and it does NOT have this
problem. I know the quick fix is to create a new account for her with a
different name and marry it up with her docs and email account, but I'd
kinda like to fix this and KNOW what went wrong.

Any ideas out there?

TIA,

--
Mike Webb
Platte River Whooping Crane Maintenance Trust, Inc.
a conservation non-profit (501 (c)(3)) organization
Wood River, NE


.



Relevant Pages

  • XP Logon nightmare
    ... I am having the exact same error message. ... Logon failure: user account restriction. ... Not only are the other four computers are still able to access the ...
    (microsoft.public.windowsxp.security_admin)
  • Re: Im Stumped...
    ... I attempt to access the server via the UNC path. ... On 6 workstations I had no problems but 2 of ... involved plus I didnt feel the problem was the account I was using since ... I tried renaming on of the computers, ...
    (microsoft.public.windows.server.active_directory)
  • Re: Im Stumped...
    ... I attempt to access the server via the UNC path. ... On 6 workstations I had no problems but 2 of ... involved plus I didnt feel the problem was the account I was using since ... I tried renaming on of the computers, ...
    (microsoft.public.windows.server.active_directory)
  • Re: Administrator cant logon to his domain workstation as administrator
    ... servers are pointing to your internal DNS server. ... > Then I noticed it would not logon when rebooted. ... > The administrator cant login to his own account ... > No domain computers can get to me, ...
    (microsoft.public.win2000.active_directory)
  • Re: How to Remove Ghost DC from AD
    ... > Users and Computers, in the Domain Controllers container, ... > It seems that it cannot be deleted as the server is registered ... > not this account is to be trusted for delagation". ... > Can anybody help me to remove this Ghost DCs from the Active ...
    (microsoft.public.win2000.active_directory)