Event 4717 - Authentication Policy Change Expand / Collapse
Author
Message
Posted 1/16/2011 6:12:42 PM
Forum Newbie

Forum NewbieForum NewbieForum NewbieForum NewbieForum NewbieForum NewbieForum NewbieForum Newbie

Group: Forum Members
Last Login: 1/15/2011 4:26:36 PM
Posts: 1, Visits: 0
Hello,

I did a recovery and noticed a ton of audit changes in the Event Viewer/Security. I've added the one below and wonder what it means. I haven't been able to find any answers on-line. Would appreciate an answer. Thanks much.

1) Event 4717 – Authentication Policy Change 1/14/2011 10:33:46 AM

System security access was granted to an account.

Subject:
Security ID: SYSTEM
Account Name: ____-PC$
Account Domain: WORKGROUP
Logon ID: 0x3e7

Account Modified:
Account Name: ____-PC\Guest

Access Granted:
Access Right: SeDenyRemoteInteractiveLogonRight

I'm wondering about the Account Modified ("Guest") and the Access Right (SeDenyRemoteInteractiveLogonRight). Thanks again.
Post #551
Posted 2/10/2011 10:18:14 AM
Expert

ExpertExpertExpertExpertExpertExpertExpertExpert

Group: Administrators
Last Login: 4/20/2009 7:57:33 AM
Posts: 329, Visits: 0
it looks like a group policy object or some other configuration process (but probably group policy because notice the subject is SYSTEM) assigned a deny logon right to Guest.  Nothing wrong with that.  Run a Group Policy Results Wizard report on that computer with GPMC to find out if and what GPO that policy came from.
Post #586
« Prev Topic | Next Topic »


Permissions Expand / Collapse

All times are GMT -5:00, Time now is 2:44pm