Windows 2003 Failure Audit Event ID:529


hi all,

i receiving failure audits on exchange server every 1.5hours or legitimate ad user machine on network user not log on to.

servers
domain controller 2003 sp2 32bit
exchange server 2003 sp2 32bit
application server 2003 sp2 32bit

i have checked outlook exchange account name , scheduled tasks on pc in question and the logs not reveal clues.

event type: failure audit
event source: security
event category: logon/logoff 
event id: 529
date: 15/05/2012
time: 12:49:19 pm
user: nt authority\system
computer: exchangeserver
description:
logon failure:
reason: unknown user name or bad password
user name: (ad username)
domain: exchangeserver
logon type: 3
logon process: ntlmssp 
authentication package: ntlm
workstation name: computername
caller user name: -
caller domain: -
caller logon id: -
caller process id: -
transited services: -
source network address: 192.168.10.29
source port: 1420

any appreciated.

cheers,
shaun 

hi shaun,

thank post.

since event occurs every 1.5 hours, suggest check schedule task first. troubleshooting account lockout follow article below.
http://blogs.technet.com/b/instan/archive/2009/09/01/troubleshooting-account-lockout-the-pss-way.aspx

if there more inquiries on issue, please feel free let know.

regards


rick tan

technet community support



Windows Server  >  Security



Comments

Popular posts from this blog

Error: 0x80073701 when trying to add Print Services Role in Windows 2012 Standard

Disconnecting from a Windows Server 2012 R2 file sharing session on a Windows 7,8,10 machine

Event ID 64,77,1008 Certificates Events Windows Server 2008, 2008R2