Go Premium for a chance to win a PS4. Enter to Win

x
?
Solved

Computer still contacting domain even though we removed it from domain

Posted on 2012-03-16
4
Medium Priority
?
394 Views
Last Modified: 2012-03-16
We had this computer on our domain but we are redeploying it as a Kiosk machine.  The Kiosk's have no reason to be on our domain for security reasons.  I've installed SiteKiosk v8 software on this Windows 7 64bit machine.  Everything works great except when I log into the LOCAL user it appears as if the machine is still contacting our domain.  We use EventSentry and I get the following message every time I log onto this kiosk box with a local user.


EVENT #      65036788
EVENT LOG      Security
EVENT TYPE      Audit Failure
SOURCE      Security
CATEGORY      Logon/Logoff
EVENT ID      529
USERNAME      NT AUTHORITY\SYSTEM
COMPUTERNAME        -our domain controller name-
DATE / TIME        3/16/2012 9:16:29 AM
MESSAGE      Logon Failure:
Reason: Unknown user name or bad password
User Name: SiteKiosk
Domain: KIOSK2
Logon Type: 3
Logon Process: NtLmSsp
Authentication Package: NTLM
Workstation Name: KIOSK2
Caller User Name: -
Caller Domain: -
Caller Logon ID: -
Caller Process ID: -
Transited Services: -
Source Network Address: 10.1.3.162
Source Port: 0


The thing is like I said, I removed this machine from the domain. I changed it to a kiosks WORKGROUP and renamed it at the same time.  What on this machine is trying to contact the domain at logon?
0
Comment
Question by:ITdiamond
  • 2
4 Comments
 
LVL 2

Expert Comment

by:ZachAtak
ID: 37729410
Could be a service, a mapped drive or anything else thats trying to reach a resource on your domain.
0
 
LVL 7

Accepted Solution

by:
withtu earned 2000 total points
ID: 37729693
You can use NetMon to track the traffic to domain controller which will tell you that what process is connecting.
0
 

Author Comment

by:ITdiamond
ID: 37729959
Ah ok it looks like it was related to Desktop Authority Script Logic CBM Service (Computer Based Management).

We use Script Logic's Desktop Authority and I just uninstalled everything related to it.  No more errors!
0
 
LVL 7

Expert Comment

by:withtu
ID: 37730145
@ITdiamond, great news! You can also check local Group Policy results to ensure all GPO settings are restored to default.
0

Featured Post

NEW Veeam Backup for Microsoft Office 365 1.5

With Office 365, it’s your data and your responsibility to protect it. NEW Veeam Backup for Microsoft Office 365 eliminates the risk of losing access to your Office 365 data.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Uncontrolled local administrators groups within any organization pose a huge security risk. Because these groups are locally managed it becomes difficult to audit and maintain them.
Active Directory can easily get cluttered with unused service, user and computer accounts. In this article, I will show you the way I like to implement ADCleanup..
This Micro Tutorial will give you a basic overview of Windows DVD Burner through its features and interface. This will be demonstrated using Windows 7 operating system.
Attackers love to prey on accounts that have privileges. Reducing privileged accounts and protecting privileged accounts therefore is paramount. Users, groups, and service accounts need to be protected to help protect the entire Active Directory …
Suggested Courses

971 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question