Click here to get back home

security account login failed

 HomeNewsGroups | Search | About
 microsoft.public.windows.server.security    Post an article   get this group's latest topics as an RSS feed add this group's latest topics to your My MSN content add this group's latest topics to your My Yahoo content
Subject Author Date
security account login failed BT 02-07-2007
Posted by BT on February 7, 2007, 2:02 am
Please log in for more thread options
Hi all

I found that many failed security audit in the event log. For example:-
The logon to account: administrator by:
MICROSOFT_AUTHENTICATION_PACKAGE_V1_0 from workstation: WRK001 failed. The
error code was: 3221225578

The logon to account: administrator by:
MICROSOFT_AUTHENTICATION_PACKAGE_V1_0 from workstation: WRK002 failed. The
error code was: 3221225578

...

They are come from many different pc.

Can someone explain to me what is happening?

Thanks
BT


Posted by Wayne Anderson on February 7, 2007, 2:20 am
Please log in for more thread options
An incorrect password is being specified for the administrator account. This
this on a DC event log or a local event log?

--
Wayne Anderson
http://blog.avanadeadvisor.com/blogs/waynea/


"BT" wrote:

> Hi all
>
> I found that many failed security audit in the event log. For example:-
> The logon to account: administrator by:
> MICROSOFT_AUTHENTICATION_PACKAGE_V1_0 from workstation: WRK001 failed. The
> error code was: 3221225578
>
> The logon to account: administrator by:
> MICROSOFT_AUTHENTICATION_PACKAGE_V1_0 from workstation: WRK002 failed. The
> error code was: 3221225578
>
> ...
>
> They are come from many different pc.
>
> Can someone explain to me what is happening?
>
> Thanks
> BT
>

Posted by BT on February 7, 2007, 2:58 am
Please log in for more thread options
It is logged in the DC event.
All user using their domain user account to connect the network, not the
administrator account.

Any idea?
Thanks

BT

> An incorrect password is being specified for the administrator account.
> This
> this on a DC event log or a local event log?
>
> --
> Wayne Anderson
> http://blog.avanadeadvisor.com/blogs/waynea/
>
>
> "BT" wrote:
>
>> Hi all
>>
>> I found that many failed security audit in the event log. For example:-
>> The logon to account: administrator by:
>> MICROSOFT_AUTHENTICATION_PACKAGE_V1_0 from workstation: WRK001 failed.
>> The
>> error code was: 3221225578
>>
>> The logon to account: administrator by:
>> MICROSOFT_AUTHENTICATION_PACKAGE_V1_0 from workstation: WRK002 failed.
>> The
>> error code was: 3221225578
>>
>> ...
>>
>> They are come from many different pc.
>>
>> Can someone explain to me what is happening?
>>
>> Thanks
>> BT
>>


Posted by Wayne Anderson on February 7, 2007, 11:28 am
Please log in for more thread options
Is it possibly common on the workstations producing the error to log in with
the local administrator account for some tasks? This could be caused by the
local administrator attempting access to a domain-authenticated resource
without specifically specifying alternate credentials before hand.

Are these workstations in use by staff in the IT environment? Without
knowing the time span in which the event log errors are developing or the
size of your environment, its tough to define the threshold for what should
be acceptable for the "fat finger factor" by your own staff.
--
Wayne Anderson
http://blog.avanadeadvisor.com/blogs/waynea/


"BT" wrote:

> It is logged in the DC event.
> All user using their domain user account to connect the network, not the
> administrator account.
>
> Any idea?
> Thanks
>
> BT
>
> > An incorrect password is being specified for the administrator account.
> > This
> > this on a DC event log or a local event log?
> >
> > --
> > Wayne Anderson
> > http://blog.avanadeadvisor.com/blogs/waynea/
> >
> >
> > "BT" wrote:
> >
> >> Hi all
> >>
> >> I found that many failed security audit in the event log. For example:-
> >> The logon to account: administrator by:
> >> MICROSOFT_AUTHENTICATION_PACKAGE_V1_0 from workstation: WRK001 failed.
> >> The
> >> error code was: 3221225578
> >>
> >> The logon to account: administrator by:
> >> MICROSOFT_AUTHENTICATION_PACKAGE_V1_0 from workstation: WRK002 failed.
> >> The
> >> error code was: 3221225578
> >>
> >> ...
> >>
> >> They are come from many different pc.
> >>
> >> Can someone explain to me what is happening?
> >>
> >> Thanks
> >> BT
> >>
>

Posted by BT on February 7, 2007, 8:43 pm
Please log in for more thread options
Yes, these workstations is used by our company staff.

Thanks for your explanation.

BT

> Is it possibly common on the workstations producing the error to log in
> with
> the local administrator account for some tasks? This could be caused by
> the
> local administrator attempting access to a domain-authenticated resource
> without specifically specifying alternate credentials before hand.
>
> Are these workstations in use by staff in the IT environment? Without
> knowing the time span in which the event log errors are developing or the
> size of your environment, its tough to define the threshold for what
> should
> be acceptable for the "fat finger factor" by your own staff.
> --
> Wayne Anderson
> http://blog.avanadeadvisor.com/blogs/waynea/
>
>
> "BT" wrote:
>
>> It is logged in the DC event.
>> All user using their domain user account to connect the network, not the
>> administrator account.
>>
>> Any idea?
>> Thanks
>>
>> BT
>>
>> > An incorrect password is being specified for the administrator account.
>> > This
>> > this on a DC event log or a local event log?
>> >
>> > --
>> > Wayne Anderson
>> > http://blog.avanadeadvisor.com/blogs/waynea/
>> >
>> >
>> > "BT" wrote:
>> >
>> >> Hi all
>> >>
>> >> I found that many failed security audit in the event log. For
>> >> example:-
>> >> The logon to account: administrator by:
>> >> MICROSOFT_AUTHENTICATION_PACKAGE_V1_0 from workstation: WRK001 failed.
>> >> The
>> >> error code was: 3221225578
>> >>
>> >> The logon to account: administrator by:
>> >> MICROSOFT_AUTHENTICATION_PACKAGE_V1_0 from workstation: WRK002 failed.
>> >> The
>> >> error code was: 3221225578
>> >>
>> >> ...
>> >>
>> >> They are come from many different pc.
>> >>
>> >> Can someone explain to me what is happening?
>> >>
>> >> Thanks
>> >> BT
>> >>
>>


Similar ThreadsPosted
Login Script Question - Failed Login Count, Location, and Method October 5, 2005, 6:28 pm
Hundreds of failed login attempts March 30, 2006, 1:13 pm
c2 failed login correlation to an origination IP/host ? June 22, 2005, 11:35 am
windows 2003 user login failed locally October 16, 2005, 1:50 pm
Single login per account possiable? September 28, 2005, 9:07 pm
ACL login security access July 5, 2005, 1:06 am
Changing the Administrator account username for security? June 15, 2005, 10:20 am
Adding Computer account to folder security March 20, 2006, 9:19 am
Local account home folder security win2003 June 28, 2005, 4:10 pm
Reading Security Event Logs with Service Account November 15, 2007, 7:36 pm

Our other projects:

Art Dolls, Fairies and Mermaids - Sunnyfaces.net

Roy's Linux, Programming and Search Engines messages

1-Script XML SitemapXML Sitemap