Local user account trying to authenticate against Domain Server


i have started implementing ad (2012) small company.  beginning server infrastructure.  seeing lot of generated error messages on domain controller failed logon attempts local accounts these servers.  in particular case (2008r2 server)these generated execution of task using local user account.  balancing application , security risks particular server have blend of local , domain user accounts.

what confuses me, there no logon failure messages on server @ domain level.  seems me server default tries authenticate local user against domain controller first.  fails , reports , validates against lsa , succeeds. 

has seem this? 

on domain controller see:

  <eventid>4625</eventid>
  <version>0</version>
  <level>0</level>
  <task>12544</task>
  <opcode>0</opcode>
  <keywords>0x8010000000000000</keywords>
  <timecreated systemtime="2016-05-27t20:00:00.329124100z" />
  <eventrecordid>9763091</eventrecordid>
  <correlation />
  <execution processid="612" threadid="7512" />
  <channel>security</channel>
  <computer>server1.domainname1</computer>
  <security />
  </system>
- <eventdata>
  <data name="subjectusersid">s-1-0-0</data>
  <data name="subjectusername">-</data>
  <data name="subjectdomainname">-</data>
  <data name="subjectlogonid">0x0</data>
  <data name="targetusersid">s-1-0-0</data>
  <data name="targetusername">username1</data>
  <data name="targetdomainname">server1</data>
  <data name="status">0xc000006d</data>
  <data name="failurereason">%%2313</data>
  <data name="substatus">0xc0000064</data>
  <data name="logontype">3</data>
  <data name="logonprocessname">ntlmssp</data>
  <data name="authenticationpackagename">ntlm</data>
  <data name="workstationname">server1</data>
  <data name="transmittedservices">-</data>
  <data name="lmpackagename">-</data>
  <data name="keylength">0</data>
  <data name="processid">0x0</data>
  <data name="processname">-</data>
  <data name="ipaddress">server1ip</data>
  <data name="ipport">61936</data>
  </eventdata>


believe have correlated server1 event messages
  <eventid>4624</eventid>
  <version>0</version>
  <level>0</level>
  <task>12544</task>
  <opcode>0</opcode>
  <keywords>0x8020000000000000</keywords>
  <timecreated systemtime="2016-05-27t20:00:00.106741400z" />
  <eventrecordid>7965325</eventrecordid>
  <correlation />
  <execution processid="1016" threadid="840" />
  <channel>security</channel>
  <computer>pa03.corp.battea.com</computer>
  <security />
  </system>
- <eventdata>
  <data name="subjectusersid">s-1-5-18</data>
  <data name="subjectusername">server1$</data>
  <data name="subjectdomainname">domainname1</data>
  <data name="subjectlogonid">0x3e7</data>
  <data name="targetusersid">s-1-5-21-100020199-4143351322-3718560211-1005</data>
  <data name="targetusername">username1</data>
  <data name="targetdomainname">server1</data>
  <data name="targetlogonid">0x7dd49b54</data>
  <data name="logontype">4</data>
  <data name="logonprocessname">advapi</data>
  <data name="authenticationpackagename">negotiate</data>
  <data name="workstationname">server1</data>
  <data name="logonguid">{00000000-0000-0000-0000-000000000000}</data>
  <data name="transmittedservices">-</data>
  <data name="lmpackagename">-</data>
  <data name="keylength">0</data>
  <data name="processid">0x4cc</data>
  <data name="processname">c:\windows\system32\svchost.exe</data>
  <data name="ipaddress">-</data>
  <data name="ipport">-</data>
  </eventdata>
  </event>

or/and
  <eventid>4672</eventid>
  <version>0</version>
  <level>0</level>
  <task>12548</task>
  <opcode>0</opcode>
  <keywords>0x8020000000000000</keywords>
  <timecreated systemtime="2016-05-27t20:00:00.106741400z" />
  <eventrecordid>7965326</eventrecordid>
  <correlation />
  <execution processid="1016" threadid="840" />
  <channel>security</channel>
  <computer>server1.domainname1</computer>
  <security />
  </system>
- <eventdata>
  <data name="subjectusersid">s-1-5-21-100020199-4143351322-3718560211-1005</data>
  <data name="subjectusername">username1</data>
  <data name="subjectdomainname">server1</data>
  <data name="subjectlogonid">0x7dd49b54</data>
  <data name="privilegelist">sesecurityprivilege setakeownershipprivilege seloaddriverprivilege sebackupprivilege serestoreprivilege sedebugprivilege sesystemenvironmentprivilege seimpersonateprivilege</data>
  </eventdata>

confused,

mark



it may depend on particular task does. if trying use network resources such shares may expected. if task doing local things use system account.

 

 

 



regards, dave patrick ....
microsoft certified professional
microsoft mvp [windows server] datacenter management

disclaimer: posting provided "as is" no warranties or guarantees, , confers no rights.



Windows Server  >  Directory Services



Comments

Popular posts from this blog

CRL Revocation always failed

Failed to query the results of bpa xpath

0x300000d errors in Microsoft Remote Desktop client