Security Event ID 643

  • Thread starter Dennis Rice \(MVP\)
  • Start date
D

Dennis Rice \(MVP\)

I have a client getting repeated (every five minutes)
Event ID 643 with a Source of "Security" in the Security
Log Event viewer. Here is the event:

*******************************************

Event Type: Success Audit
Event Source: Security
Event Category: Account Management
Event ID: 643
Date: 9/11/2003
Time: 3:50:56 PM
User: NT AUTHORITY\SYSTEM
Computer: SERVER
Description:
Domain Policy Changed: Password Policy modified
Domain: Domain
Domain ID: Domain\
Caller User Name: SERVER$
Caller Domain: Domain
Caller Logon ID: (0x0,0x3E7)
Privileges: -
******************************************

I cannot figure out what is causing this event. Anyone
have ideas on getting rid of this? I'm uncomfortable not
knowing what is causing this.....

Thanks!

Dennis Rice (MVP)
 
S

Steven L Umbach

Domain controllers update their policy every five minutes, which leads me to
believe there is a problem with that. Are there any other error Event ID's
in the application or system log that repeat every five miniutes that may be
related? I would run netdiag and dcdiag /v on that domain controller looking
for failed tests. --- Steve
 
E

Eric Fitzgerald [MSFT]

It's not a problem, it's by design, we're improving the design ;-)

--
Eric Fitzgerald
Program Manager, Windows Auditing
Microsoft Corporation

The above message is provided "AS-IS" with no warranties, and confers no
rights.
 

Ask a Question

Want to reply to this thread or ask your own question?

You'll need to choose a username for the site, which only take a couple of moments. After that, you can post your question and our members will help you out.

Ask a Question

Top