Registry Question

  • Thread starter Thread starter GX
  • Start date Start date
G

GX

Hello,

I'm using Cisco Security Agent to monitor the boxes on my domain. Once of
the messages received was the following. Anyone knows why a wwindows box
will do these functions?

The process 'C:\WINNT\system32\lsass.exe' (as user NT AUTHORITY\SYSTEM)
modified the registry key '\REGISTRY\MACHINE\SAM\SAM\Domains\Account' and
value 'F'.

Thanks

GX
 
Sounds like the machine updated its domain account, likely
by changing the password as is done periodically if not shut
off. The account represents the machine's domain membership.
 

Ask a Question

Want to reply to this thread or ask your own question?

You'll need to choose a username for the site, which only take a couple of moments. After that, you can post your question and our members will help you out.

Ask a Question

Back
Top