Registry Question

  • Thread starter Thread starter GX
  • Start date Start date
G

GX

Hello,

I'm using Cisco Security Agent to monitor the boxes on my domain. Once of
the messages received was the following. Anyone knows why a wwindows box
will do these functions?

The process 'C:\WINNT\system32\lsass.exe' (as user NT AUTHORITY\SYSTEM)
modified the registry key '\REGISTRY\MACHINE\SAM\SAM\Domains\Account' and
value 'F'.

Thanks

GX
 
Sounds like the machine updated its domain account, likely
by changing the password as is done periodically if not shut
off. The account represents the machine's domain membership.
 
Back
Top