Event ID : 643

  • Thread starter Thread starter Rohit Arora
  • Start date Start date
R

Rohit Arora

We've changed the Password Domain Policy. The issue is
that we're receiving lot of success audit event (Domain
Policy changed: Password Policy modified) in security log
for event id 643. This is happening on all servers in the
domain and is happening repeatedely everyday. Is this
normal? What are the reasons for such events.

Thanks..Rohit
 
When you audit for "policy changes" and the pw policy is changed it will
generate those 643's as the specific audit mechanism for pw polciies doesn't
differentiate between a policy change and a policy refresh.. They are
normal expected behavior.

--
David Brandt
Microsoft Corporation

This posting is provided "AS IS" with no warranties, and confers no rights.
Please do not send e-mail directly to this alias. This alias is for
newsgroup purposes only.
 
Thanks David
Does that mean that policy refresh will continue to occur
on a regular basis and whats the reason behind the
constant policy refresh.

Regards..Rohit
 
Back
Top