Event ID : 643

R

Rohit Arora

We've changed the Password Domain Policy. The issue is
that we're receiving lot of success audit event (Domain
Policy changed: Password Policy modified) in security log
for event id 643. This is happening on all servers in the
domain and is happening repeatedely everyday. Is this
normal? What are the reasons for such events.

Thanks..Rohit
 
D

David Brandt [MSFT]

When you audit for "policy changes" and the pw policy is changed it will
generate those 643's as the specific audit mechanism for pw polciies doesn't
differentiate between a policy change and a policy refresh.. They are
normal expected behavior.

--
David Brandt
Microsoft Corporation

This posting is provided "AS IS" with no warranties, and confers no rights.
Please do not send e-mail directly to this alias. This alias is for
newsgroup purposes only.
 
R

Rohit Arora

Thanks David
Does that mean that policy refresh will continue to occur
on a regular basis and whats the reason behind the
constant policy refresh.

Regards..Rohit
 

Ask a Question

Want to reply to this thread or ask your own question?

You'll need to choose a username for the site, which only take a couple of moments. After that, you can post your question and our members will help you out.

Ask a Question

Top