Failed Logon Guest Account via Explorer.exe


windows server 2008 r2 -> domain machine local guest account.  local security policy has guest disbaled, gpo has guest renamed not defined on disabled/enabled.

i'll focus on 1 machine, has occurred on several other machines.  seeing logon failures in windows event logs associated our guest account.  drilling these eventlogs, i've foudn local guest account, , calling process explorer.exe:

logname=security
sourcename=microsoft windows security auditing.
eventcode=4625
eventtype=0
type=information
computername=anonaserver.ncsgroup.bnsf.com
taskcategory=logon
opcode=info
recordnumber=397235473
keywords=audit failure
message=an account failed to log on.

subject:
security id: anonaserver\anonauser
account name:  anonauser
account domain: anonaserver

logon id: 0x16f84c6

logon type: 3

account for which logon failed:
security id: null sid
account name:  guest
account domain:  anonaserver

failure information:
failure reason: account currently disabled.
status: 0xc000006e
sub status: 0xc0000072

process information:
caller process id: 0x1640
caller process name: c:\windows\explorer.exe

network information:
workstation name: anonaserver

source network address: -
source port: -

detailed authentication information:
logon process: advapi 
authentication package: negotiate
transited services: -
package name (ntlm only): -

i've included entire output.  i drilled machine, found person security id associated calling process.  opened procexp64.exe, found pid, did bring front , says, windows explorer.exe.  1 had been opened "pictures" under users documents.  said hadn't navigated windows explorer process yet (fellow admin, he accurate).

either way, doesn't seem rare of issue, having trouble nailing down exactely occurring , more important how put end it.  gpo info:    network access: sharing , security model local accounts: classic

accounts: guest account status: not defined

accounts: rename guest account: enabled , renamed

thanks

hi,

event, can read user anonauser trying logon network. please check whether rdp session. if not, recommend doing full safety scan on machine check if it's infected. 

thanks, brian


please remember click “mark answer” on post helps you, , click “unmark answer” if marked post not answer question. can beneficial other community members reading thread.



Windows Server  >  Group Policy



Comments

Popular posts from this blog

CRL Revocation always failed

Failed to query the results of bpa xpath

0x300000d errors in Microsoft Remote Desktop client