AUDIT_FAILURE(4769): Microsoft-Windows-Security-Auditing

I've been receiving a lot of Auditing events for 4769 on our Win2k8 DC and  researched the problem.  We used the following command to turn off the events as they were messing with our other security solutions:

1.) auditpol /get /category:"Account Logon" /subcategory:"Kerberos Service Ticket Operations"
Result:  We see it is set for "Success and Failure".
2.) We set the flag for JUST success:
auditpol /set /category:"Account Logon" /subcategory:"Kerberos Service Ticket Operations" /failure:disable
Result:  As expected Setting only shows "Success".


This works great for a 5-7 hours, but somehow it flips back throughout the night and we start getting a flood of these messages again.  There are NO other corresponding events in the Event Manager that would explain this flag being reset.
IMEDECSAsked:
Who is Participating?

[Webinar] Streamline your web hosting managementRegister Today

x
 
IMEDECSConnect With a Mentor Author Commented:
Resolved.  It was a domain GPO that was causing it to reset.
0
 
Netman66Commented:
Can you please post the event itself?

0
 
Netman66Commented:
OK, however you should not be getting an enormous amount of these to begin with.

0
All Courses

From novice to tech pro — start learning today.