Directory Service Access

  • Thread starter Thread starter Guest
  • Start date Start date
G

Guest

I Added a Windows 2003 server running Exchange 2003 (member server) to my
windows 2000 domain. when a user logs on with a wrong password or username
The local workstation records a logon failure(Event ID 529) to the local
security event log, however the Domain server security event log shows no
login failure (Event ID 529), but instead logs an event ID 565.

Here is a copy of the event on the Domain Security log:

Event Type: Failure Audit
Event Source: Security
Event Category: Directory Service Access
Event ID: 565
Date: 8/8/2005
Time: 10:08:10 AM
User: TASBCLS\XCH-CLS$
Computer: TASBCLS-01
Description:
Object Open:
Object Server: DS
Object Type: configuration
Object Name: CN=Configuration,DC=TASBCLS,DC=com
New Handle ID: -
Operation ID: {0,62436668}
Process ID: 284
Primary User Name: TASBCLS-01$
Primary Domain: TASBCLS
Primary Logon ID: (0x0,0x3E7)
Client User Name: XCH-CLS$
Client Domain: TASBCLS
Client Logon ID: (0x0,0x3CA88)
Accesses Control Access

Privileges -

Properties:
DELETE
WRITE_OWNER
Delete Child
List Contents
Write Property
Delete Tree
Manage Replication Topology

----------------------------------------------------------------------------------------

Why is this happening?

Thanks,

John
 
Back
Top