540 Events on Domain controllers Expand / Collapse
Author
Message
Posted 1/12/2011 11:36:11 AM
Forum Newbie

Forum NewbieForum NewbieForum NewbieForum NewbieForum NewbieForum NewbieForum NewbieForum Newbie

Group: Forum Members
Last Login: 2/3/2011 10:26:59 AM
Posts: 2, Visits: 3
I'm seeing activity on domain controllers that show the machine name SYSNAMEHERE$ as the User Name and the Computer Name is the domain controller. They are 540 type 8 logins that are successful, however, I'm trying to understand what is generating the event because I know that these users do not have proper credentials to log into a domain controller. Is this some Windows background foo? Perhaps Windows logon scripts, etc.?
Post #548
Posted 1/25/2011 5:06:32 PM
Forum Newbie

Forum NewbieForum NewbieForum NewbieForum NewbieForum NewbieForum NewbieForum NewbieForum Newbie

Group: Forum Members
Last Login: 2/3/2011 10:26:59 AM
Posts: 2, Visits: 3
I answered my own question:

From: http://technet.microsoft.com/en-us/library/cc787567%28WS.10%29.aspx

Additionally, interactive logons to a member server or workstation that use a domain account generate a logon event on the domain controller as the logon scripts and policies are retrieved when a user logs on. For more information about account logon events, see Audit account logon events.
Post #555
« Prev Topic | Next Topic »


Permissions Expand / Collapse

All times are GMT -5:00, Time now is 5:00pm