Link to home
Start Free TrialLog in
Avatar of hypercube
hypercubeFlag for United States of America

asked on

Windows Network logon (Type 3) failure internal to workstation by disabled "Guest" account.

I'm still chasing 4625 failed logons (Type 3) as in:
https://www.experts-exchange.com/questions/29168087/Type-3-logon-failures-4625-from-old-credentials.html

This is a slightly different instance of the reports I'm getting:
Reported Username is Guest on a computer where the Guest account is inactivated.
Reported "Remote Device" is the workstation itself - not another one.
Reported "Domain" is the same workstation name - not another one.

So, yes, attempts to logon with Guest should fail because Guest is inactivated.
But why would a workstation be having logon attempts unto itself when I think if Guest as being a Network logon attempt.
And, yes, these are "network logons" (Type 3, right?).
So why are they coming from within the workstation?

In this case, it happened on Friday starting around time for people to come to work at 8:30  and it persisted until 11:50.  There were over 400 events, some of which occurred within the same second - spaced variably with gaps up to an hour.

This is happening on a few workstations, although not to this degree.
In this case, it's not an "old credential".and yet the results are very similar to the earlier question's situation.

I still haven't found the smoking gun.
Avatar of Kent W
Kent W
Flag of United States of America image

On the event log entry, have you checked the Failure Information Status and Sub Status code?
That may give more of a clue. You can check the codes here:

https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventID=4625
ASKER CERTIFIED SOLUTION
Avatar of hypercube
hypercube
Flag of United States of America image

Link to home
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
Start Free Trial
That is awesome. I'm glad you were at least pointed in the right direction.
Avatar of hypercube

ASKER

Thanks again!
I'm going to open the same question as what I found was about hidden credentials and NOT really to the point of this question which was about Guest attempts.