Solved

Event ID 644 not showing up on event Security Log.

Posted on 2007-03-26
4
1,034 Views
Last Modified: 2013-12-04
I have a Windows Server 2003 SP1 Domain Controller. We have one legacy NT4 BDC, no other Domain Controllers.

Whenever an account is locked, for instance by the user trying more than 5 passwords, the account lockout does not show up in the event Security Log.

To test this I tried it in my test environment, with just one 2003 DC and one XP SP2 client and the same thing happens I get no 644s. I do get 539s when I attempt to logon the client after the account is locked.

In the Default Domain Security setting Audit Policy I have everything set to audit, success and failure.

I don’t wish to make any changes to production until I can get this working in Test.

Does anybody have any suggestions or solutions?
0
Comment
Question by:BMCKRob
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 2
  • 2
4 Comments
 
LVL 31

Expert Comment

by:Toni Uranjek
ID: 18798831
Do you get any 642s instead of 644?

Event ID:642
Description:
User Account Changed:
Account Locked.

0
 

Author Comment

by:BMCKRob
ID: 18802057
No, we are not getting any 642's either.
0
 
LVL 31

Accepted Solution

by:
Toni Uranjek earned 500 total points
ID: 18806200
How is your Audit policy set? Default Domain Controller Security Settings should have the following Audit policy set "Audit account managment" to Success, for event ID 644 to appear.
Did you check BDC logs also?
0
 

Author Comment

by:BMCKRob
ID: 18816132
That is IT!!!!  We have been working on this for weeks, none of the documentation I have read says that needs to be set. Thanks you have earned the points.
0

Featured Post

Free NetCrunch network monitor licenses!

Only on Experts-Exchange: Sign-up for a free-trial and we'll send you your permanent license!

Here is what you get: 30 Nodes | Unlimited Sensors | No Time Restrictions | Absolutely FREE!

Act now. This offer ends July 14, 2017.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Many people tend to confuse the function of a virus with the one of adware, this misunderstanding of the basic of what each software is and how it operates causes users and organizations to take the wrong security measures that would protect them ag…
Container Orchestration platforms empower organizations to scale their apps at an exceptional rate. This is the reason numerous innovation-driven companies are moving apps to an appropriated datacenter wide platform that empowers them to scale at a …
This is a high-level webinar that covers the history of enterprise open source database use. It addresses both the advantages companies see in using open source database technologies, as well as the fears and reservations they might have. In this…
There are cases when e.g. an IT administrator wants to have full access and view into selected mailboxes on Exchange server, directly from his own email account in Outlook or Outlook Web Access. This proves useful when for example administrator want…

717 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question