Click here to get back home

Successful Logon to DC local machine

 HomeNewsGroups | Search | About
 microsoft.public.windows.server.security    Post an article   get this group's latest topics as an RSS feed add this group's latest topics to your My MSN content add this group's latest topics to your My Yahoo content
Subject Author Date
Successful Logon to DC local machine r. wales 09-11-2006
Posted by r. wales on September 11, 2006, 12:31 pm
Please log in for more thread options
I have seen entries from over the weekend that show a successful logon for a
user account on the 127.0.0.1 address of my domain controller. I know for a
fact that this user was not logged on to the server, and that the users
workstation was shut down over the weekend. This entry occurs every nine
hours and fifty minutes. The event entries look like this:

Event Type:        Success Audit
Event Source:        Security
Event Category:        Account Logon
Event ID:        674
Date:                9/11/2006
Time:                5:08:15 AM
User:                NT AUTHORITY\SYSTEM
Computer:        <servername>
Description:
Service Ticket Renewed:
        User Domain:        <domainname>.LOCAL
        Service Name:        krbtgt
        Service ID:        <domainname>\krbtgt
        Ticket Options:        0x2
        Ticket Encryption Type:        0x17
        Client Address:        127.0.0.1


Posted by Steven L Umbach on September 11, 2006, 10:53 pm
Please log in for more thread options
That indicates a Kerberos service ticket renewal for some reason which are
done regularly and ten hours sounds about right. Maybe his user account
credentials are being used somewhere else in the domain other than his
workstation or his account is still logged onto another computer. I would
not consider it anything malicious.

Steve


>I have seen entries from over the weekend that show a successful logon for
>a
> user account on the 127.0.0.1 address of my domain controller. I know for
> a
> fact that this user was not logged on to the server, and that the users
> workstation was shut down over the weekend. This entry occurs every nine
> hours and fifty minutes. The event entries look like this:
>
> Event Type: Success Audit
> Event Source: Security
> Event Category: Account Logon
> Event ID: 674
> Date: 9/11/2006
> Time: 5:08:15 AM
> User: NT AUTHORITY\SYSTEM
> Computer: <servername>
> Description:
> Service Ticket Renewed:
> User Domain: <domainname>.LOCAL
> Service Name: krbtgt
> Service ID: <domainname>\krbtgt
> Ticket Options: 0x2
> Ticket Encryption Type: 0x17
> Client Address: 127.0.0.1
>



Posted by r. wales on September 12, 2006, 9:41 am
Please log in for more thread options
Thanks Steve. I watched the logs yesterday afternoon looking for the
expected entry 9.5 to 10 hours later and it didn't show up. As the user
turned their computer on and logged back in Monday morning I really wasn't
expecting it to be there. Still, it was one of those 'Hmmm...' things.
Thanks again.

"Steven L Umbach" wrote:

> That indicates a Kerberos service ticket renewal for some reason which are
> done regularly and ten hours sounds about right. Maybe his user account
> credentials are being used somewhere else in the domain other than his
> workstation or his account is still logged onto another computer. I would
> not consider it anything malicious.
>
> Steve
>
>
> >I have seen entries from over the weekend that show a successful logon for
> >a
> > user account on the 127.0.0.1 address of my domain controller. I know for
> > a
> > fact that this user was not logged on to the server, and that the users
> > workstation was shut down over the weekend. This entry occurs every nine
> > hours and fifty minutes. The event entries look like this:
> >
> > Event Type: Success Audit
> > Event Source: Security
> > Event Category: Account Logon
> > Event ID: 674
> > Date: 9/11/2006
> > Time: 5:08:15 AM
> > User: NT AUTHORITY\SYSTEM
> > Computer: <servername>
> > Description:
> > Service Ticket Renewed:
> > User Domain: <domainname>.LOCAL
> > Service Name: krbtgt
> > Service ID: <domainname>\krbtgt
> > Ticket Options: 0x2
> > Ticket Encryption Type: 0x17
> > Client Address: 127.0.0.1
> >
>
>
>

Similar ThreadsPosted
Problems with authentication and using alias to the local machine April 27, 2006, 10:22 am
Changing local admin password on a set of machine in an ad network ? June 6, 2005, 1:28 pm
Logon Script set permissions on local directory September 7, 2005, 10:27 am
Local Logon Access to Production Servers September 13, 2007, 12:04 pm
"the local policy of this system does not permit you to logon interactively" April 11, 2007, 5:15 pm
Logon/Logoff Events in Local Security Log of Terminal Server July 20, 2007, 2:39 pm
There are currently no logon servers available to service the logon request - how to fix this error? i get it when trying to access a share one hop away. April 12, 2007, 6:03 pm
Workstations showing logon failures by users can still logon? November 27, 2007, 6:56 pm
Machine does not respond. June 28, 2005, 12:42 pm
Any Way To Get Machine Name for Client in Event ID 560? November 13, 2005, 6:38 pm

Our other projects:

Art Dolls, Fairies and Mermaids - Sunnyfaces.net

Roy's Linux, Programming and Search Engines messages

1-Script XML SitemapXML Sitemap