Event IDs 642 and 644

  • Thread starter Thread starter djc
  • Start date Start date
D

djc

1) I'm looking into an account lockout issue and noticed that instead of
what I expected to be 'system', the user is listed as 'everyone'. ? I'm not
refering to the user that got locked out, but the user listed in event
viewer as the one performing the account management, which I am auditing.

Is that normal? for when an account gets locked out due to to many invalid
logon attempts?

2) even stranger (to me) is I have 2 account management events of 627
(password change attempts), one succeeded and one failed and the user listed
in event viewer was ANONYMOUS LOGON? Again, I'm not refering to the user who
was account password was being changed... but rather the logon listed as the
one doing it? I think this may be due to an Outlook Web Access issue that I
will follow up on but I figured I would through this here as well.

any info would be greatly appreciated. thanks.
 
I don't really know the answer to question one as I have not really noticed it, but
for question two it may have been a user trying to change their password before they
logged onto their computer which may use a "null" session to AD to do such, so I
would not be concerned about that entry. The link below explains a bit more on
hat. --- Steve

http://support.microsoft.com/?id=242795 --- see the last paragraph.
 
Back
Top