Local user account trying to authenticate against Domain Server
i have started implementing ad (2012) small company. beginning server infrastructure. seeing lot of generated error messages on domain controller failed logon attempts local accounts these servers. in particular case (2008r2 server)these generated execution of task using local user account. balancing application , security risks particular server have blend of local , domain user accounts.
what confuses me, there no logon failure messages on server @ domain level. seems me server default tries authenticate local user against domain controller first. fails , reports , validates against lsa , succeeds.
has seem this?
on domain controller see:
<eventid>4625</eventid>
<version>0</version>
<level>0</level>
<task>12544</task>
<opcode>0</opcode>
<keywords>0x8010000000000000</keywords>
<timecreated systemtime="2016-05-27t20:00:00.329124100z" />
<eventrecordid>9763091</eventrecordid>
<correlation />
<execution processid="612" threadid="7512" />
<channel>security</channel>
<computer>server1.domainname1</computer>
<security />
</system>
- <eventdata>
<data name="subjectusersid">s-1-0-0</data>
<data name="subjectusername">-</data>
<data name="subjectdomainname">-</data>
<data name="subjectlogonid">0x0</data>
<data name="targetusersid">s-1-0-0</data>
<data name="targetusername">username1</data>
<data name="targetdomainname">server1</data>
<data name="status">0xc000006d</data>
<data name="failurereason">%%2313</data>
<data name="substatus">0xc0000064</data>
<data name="logontype">3</data>
<data name="logonprocessname">ntlmssp</data>
<data name="authenticationpackagename">ntlm</data>
<data name="workstationname">server1</data>
<data name="transmittedservices">-</data>
<data name="lmpackagename">-</data>
<data name="keylength">0</data>
<data name="processid">0x0</data>
<data name="processname">-</data>
<data name="ipaddress">server1ip</data>
<data name="ipport">61936</data>
</eventdata>
believe have correlated server1 event messages
<eventid>4624</eventid>
<version>0</version>
<level>0</level>
<task>12544</task>
<opcode>0</opcode>
<keywords>0x8020000000000000</keywords>
<timecreated systemtime="2016-05-27t20:00:00.106741400z" />
<eventrecordid>7965325</eventrecordid>
<correlation />
<execution processid="1016" threadid="840" />
<channel>security</channel>
<computer>pa03.corp.battea.com</computer>
<security />
</system>
- <eventdata>
<data name="subjectusersid">s-1-5-18</data>
<data name="subjectusername">server1$</data>
<data name="subjectdomainname">domainname1</data>
<data name="subjectlogonid">0x3e7</data>
<data name="targetusersid">s-1-5-21-100020199-4143351322-3718560211-1005</data>
<data name="targetusername">username1</data>
<data name="targetdomainname">server1</data>
<data name="targetlogonid">0x7dd49b54</data>
<data name="logontype">4</data>
<data name="logonprocessname">advapi</data>
<data name="authenticationpackagename">negotiate</data>
<data name="workstationname">server1</data>
<data name="logonguid">{00000000-0000-0000-0000-000000000000}</data>
<data name="transmittedservices">-</data>
<data name="lmpackagename">-</data>
<data name="keylength">0</data>
<data name="processid">0x4cc</data>
<data name="processname">c:\windows\system32\svchost.exe</data>
<data name="ipaddress">-</data>
<data name="ipport">-</data>
</eventdata>
</event>
or/and
<eventid>4672</eventid>
<version>0</version>
<level>0</level>
<task>12548</task>
<opcode>0</opcode>
<keywords>0x8020000000000000</keywords>
<timecreated systemtime="2016-05-27t20:00:00.106741400z" />
<eventrecordid>7965326</eventrecordid>
<correlation />
<execution processid="1016" threadid="840" />
<channel>security</channel>
<computer>server1.domainname1</computer>
<security />
</system>
- <eventdata>
<data name="subjectusersid">s-1-5-21-100020199-4143351322-3718560211-1005</data>
<data name="subjectusername">username1</data>
<data name="subjectdomainname">server1</data>
<data name="subjectlogonid">0x7dd49b54</data>
<data name="privilegelist">sesecurityprivilege setakeownershipprivilege seloaddriverprivilege sebackupprivilege serestoreprivilege sedebugprivilege sesystemenvironmentprivilege seimpersonateprivilege</data>
</eventdata>
confused,
mark
it may depend on particular task does. if trying use network resources such shares may expected. if task doing local things use system account.
regards, dave patrick ....
microsoft certified professional
microsoft mvp [windows server] datacenter management
disclaimer: posting provided "as is" no warranties or guarantees, , confers no rights.
Windows Server > Directory Services
Comments
Post a Comment