Solved

Event ID 565 Failure Audit.  WHAT DOES IT MEAN?

Posted on 2006-06-29
4
835 Views
Last Modified: 2008-01-09
Exchange 2003, Cluster of 2 servers running 2003 Server.  I am getting some Failure Audits in the Event Log that dont make much sense.  The event ID is 565.  Lets say I have Jim, Mark, and Zach.  I will see these failure audits from Jim on Jim's account.  Same for Mark and Zach.  What I found is that I have seen these same audits only they were on Mark and Zach's account but they were caused by Jim.  I could recreate the audit if I tried to open another persons mailbox so I thought that Jim might be trying to read other people's mail.  He tells me that they were probably caused by Meeting Requests that he sent out and surprisingly they match up.  But then I found some more of these audits only they dont match up with any Meeting Requests.  Here is an example of an audit I have seen.


6/28/2006 8:26:23 AM Failure Audit Security SERVER01
  Object Open:
Object Server: Microsoft Exchange
Object Type: Microsoft Exchange Logon
Object Name: /o=Exchange2003/ou=First Administrative Group/cn=Recipients/cn=ZACH
Handle ID: -
Operation ID: {1,1835013326}
Process ID: 5240
Process Name: C:\Program Files\Exchsrvr\bin\store.exe
Primary User Name: APCLUS01$
Primary Domain: OPNT
Primary Logon ID: (0x0,0x3E7)
Client User Name: JIM
Client Domain: Domain
Client Logon ID: (0x1,0x6CEB0ED9)
Accesses: Unknown specific access (bit 8)

Privileges: -

Properties:
---
%{ab721a54-1e2f-11d0-9819-00aa0040529b}
%{bf967aba-0de6-11d0-a285-00aa003049e2}

Access Mask: 0

To me it looks like Jim is trying to access Zach's account but there is no definitive statement to this effect.  Any help would be great.
0
Comment
Question by:thelink12
  • 2
  • 2
4 Comments
 
LVL 51

Expert Comment

by:Netman66
Comment Utility
It appears that Jim is trying to open Zach's mailbox.  He may be going to File>Open>Other User's folder or he simply may have his mail client incorrectly configured.

Is there an Event Log Error number associated with that log?
0
 

Author Comment

by:thelink12
Comment Utility
That is how I reproduced the event, using file>open...  I got the 565 Event when I tried to open a mailbox I was not allowed to.  
0
 
LVL 51

Accepted Solution

by:
Netman66 earned 500 total points
Comment Utility
Ok, well that should be normal.  If you aren't delegated access by the user then it will log an access error.

As for Meeting requests causing this it's hard to say.  Meeting Requests should be a simple email, however, when the user responds to it then it should be updating the requestor's Calander with the the new attendee.  Perhaps the users have remove everyone's access to Calander or the permissions somehow are not set to default so the replies are being blocked via bad permissions.

0
 

Author Comment

by:thelink12
Comment Utility
I spent over 4 hours on the phone with Microsoft and they are saying its a known issue\Bug in Windows and will be taken care of in the next SP.  I will split the points.  Thanks for the help.
0

Featured Post

Enabling OSINT in Activity Based Intelligence

Activity based intelligence (ABI) requires access to all available sources of data. Recorded Future allows analysts to observe structured data on the open, deep, and dark web.

Join & Write a Comment

by Batuhan Cetin In this article I will be guiding through the process of removing a failed DC metadata from Active Directory (hereafter, AD) using the ntdsutil tool in a Windows Server 2003 environment. These steps are not necessary in a Win…
Many of us need to configure DHCP server(s) in their environment. We can do that simply via DHCP console on server or using MMC snap-in on each computer with Administrative Tools installed in a network. But what if we have to configure many DHCP ser…
Internet Business Fax to Email Made Easy - With eFax Corporate (http://www.enterprise.efax.com), you'll receive a dedicated online fax number, which is used the same way as a typical analog fax number. You'll receive secure faxes in your email, fr…
This video discusses moving either the default database or any database to a new volume.

744 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

8 Experts available now in Live!

Get 1:1 Help Now