Windows 2003 Failure Audit Event ID:529
Hi all,
I am receiving failure audits on an Exchange server every 1.5hours or so from a legitimate AD user but from a machine on the network that the user does not log on to.
Servers
Domain Controller 2003 SP2 32bit
Exchange Server 2003 SP2 32bit
Application Server 2003 SP2 32bit
I have checked the Outlook Exchange account name and scheduled tasks on the PC in question and the logs do not reveal any clues.
Event Type: Failure Audit
Event Source: Security
Event Category: Logon/Logoff
Event ID: 529
Date: 15/05/2012
Time: 12:49:19 PM
User: NT AUTHORITY\SYSTEM
Computer: EXCHANGESERVER
Description:
Logon Failure:
Reason:
Unknown user name or bad password
User Name:
(AD username)
Domain:
EXCHANGESERVER
Logon Type:
3
Logon Process:
NtLmSsp
Authentication Package:
NTLM
Workstation Name:
COMPUTERNAME
Caller User Name:
-
Caller Domain:
-
Caller Logon ID:
-
Caller Process ID:
-
Transited Services:
-
Source Network Address:
192.168.10.29
Source Port:
1420
Any help would be much appreciated.
Cheers,
Shaun
May 15th, 2012 12:48am
Hi Shaun,
Thank you for the post.
Since the event occurs every 1.5 hours, I suggest you check the schedule task first. Then troubleshooting account lockout follow the article below.
http://blogs.technet.com/b/instan/archive/2009/09/01/troubleshooting-account-lockout-the-pss-way.aspx
If there are more inquiries on this issue, please feel free to let us know.
RegardsRick Tan
TechNet Community Support
Free Windows Admin Tool Kit Click here and download it now
May 16th, 2012 5:31am
Hi Shaun,
Thank you for the post.
Since the event occurs every 1.5 hours, I suggest you check the schedule task first. Then troubleshooting account lockout follow the article below.
http://blogs.technet.com/b/instan/archive/2009/09/01/troubleshooting-account-lockout-the-pss-way.aspx
If there are more inquiries on this issue, please feel free to let us know.
RegardsRick Tan
TechNet Community Support
May 16th, 2012 5:41am