Avatar of MilesLogan
MilesLogan
Flag for United States of America asked on

Active Directory Built-in Administrator account

Hi EE

Any idea why I would see the Event IDs below coming from the Built-in Administrator account on mutliple DCs ?

This account is not used and I only the password to it .
events.png
Active DirectoryWindows Server 2003Windows Server 2008

Avatar of undefined
Last Comment
MilesLogan

8/22/2022 - Mon
Ram Balachandran

HI,

What is the event you are seeing ? Can you please provide Event ID / description ?

Regards,
Ram
MilesLogan

ASKER
Hello .. these are the events .. I also attached them .

EventID      Event Name
528      Successful Logon
538      User Logoff
576      Special privileges assigned to new logon successfully
552      Logon attempt using explicit credentials
537      Logon failure - The logon attempt failed for other reasons
Brian Pierce

Have you got any services or scheduled jobs set-up that use it ?
This is the best money I have ever spent. I cannot not tell you how many times these folks have saved my bacon. I learn so much from the contributors.
rwheeler23
MilesLogan

ASKER
Hi KCTS .. no to the question below .

" Have you got any services or scheduled jobs set-up that use it ?  "
Ram Balachandran

Which user has this logs ? is it from SYSTEM user ?
DCs will not have local user account
MilesLogan

ASKER
This is for the built-in MyDomain\Administrator
⚡ FREE TRIAL OFFER
Try out a week of full access for free.
Find out why thousands trust the EE community with their toughest problems.
Ram Balachandran

Did you perform runas option ?or any application was started with admin privilege?
MilesLogan

ASKER
no action has been taken with that account ..
Ram Balachandran

Is there any map drives created using this user. Also, you can clear the cached password from the  code mentioned in below link

https://www.experts-exchange.com/OS/Microsoft_Operating_Systems/A_448-How-to-DELETE-Windows-Local-Domain-Cached-Credentials.html
Your help has saved me hundreds of hours of internet surfing.
fblack61
MilesLogan

ASKER
No mapped drives , no services , nothing .. No one knows the password so why its so strange that we would see those events coming from that account on some of the DCs.
SOLUTION
Ram Balachandran

THIS SOLUTION ONLY AVAILABLE TO MEMBERS.
View this solution by signing up for a free trial.
Members can start a 7-Day free trial and enjoy unlimited access to the platform.
See Pricing Options
Start Free Trial
GET A PERSONALIZED SOLUTION
Ask your own question & get feedback from real experts
Find out why thousands trust the EE community with their toughest problems.
SOLUTION
Pramod Ubhe

THIS SOLUTION ONLY AVAILABLE TO MEMBERS.
View this solution by signing up for a free trial.
Members can start a 7-Day free trial and enjoy unlimited access to the platform.
See Pricing Options
Start Free Trial
⚡ FREE TRIAL OFFER
Try out a week of full access for free.
Find out why thousands trust the EE community with their toughest problems.
SOLUTION
compdigit44

THIS SOLUTION ONLY AVAILABLE TO MEMBERS.
View this solution by signing up for a free trial.
Members can start a 7-Day free trial and enjoy unlimited access to the platform.
See Pricing Options
Start Free Trial
⚡ FREE TRIAL OFFER
Try out a week of full access for free.
Find out why thousands trust the EE community with their toughest problems.
ASKER CERTIFIED SOLUTION
Venkat Suresh

THIS SOLUTION ONLY AVAILABLE TO MEMBERS.
View this solution by signing up for a free trial.
Members can start a 7-Day free trial and enjoy unlimited access to the platform.
See Pricing Options
Start Free Trial
⚡ FREE TRIAL OFFER
Try out a week of full access for free.
Find out why thousands trust the EE community with their toughest problems.
MilesLogan

ASKER
Thank you all for the great info .. I will work with these ideas and post back .