Windows Security Log Event ID 529

Operating Systems Windows Server 2000
Windows 2003 and XP
CategoryLogon/Logoff
Type Failure
Corresponding events
in Windows 2008
and Vista
4625  

529: Logon Failure - Unknown user name or bad password

On this page

Event 529 is logged on the workstation or server where the user failed to log on.

The Logon Type will enable you to determine if the user was present at this computer or elsewhere on the network.  The following Logon Types are possible:

Logon Type
Description
2
 Interactive (logon at keyboard and screen of system) Windows 2000 records Terminal Services logon as this type rather than Type 10.
3
Network (i.e. connection to shared folder on this computer from elsewhere on network or IIS logon - Never logged by 528 on W2k and forward. See event 540)
4
Batch (i.e. scheduled task)
5
Service (Service startup)
7
Unlock (i.e. unnattended workstation with password protected screen saver)
8
NetworkCleartext (Logon with credentials sent in the clear text. Most often indicates a logon to IIS with "basic authentication") See this article for more information.
9
NewCredentials
10
RemoteInteractive (Terminal Services, Remote Desktop or Remote Assistance)
11
CachedInteractive (logon with cached domain credentials such as when logging on to a laptop when away from the network)

Free Security Log Resources by Randy

Description Fields in 529

  • User Name:
  • Domain:
  • Logon Type:
  • Logon Process:
  • Authentication Package: 
  • Workstation Name:

The following fields are added with Windows Server 2003 

  • Caller User Name:
  • Caller Domain:
  • Caller Logon ID:
  • Caller Process ID:
  • Transited Services:
  • Source Network Address:
  • Source Port:

Supercharger Enterprise


 

Examples of 529

Logon Failure
Reason: Unknown user name or bad password
User Name: %1
Domain: %2
Logon Type: %3
Logon Process: %4
Authentication Package: %5
Workstation Name: %6

Windows Server 2003 adds these fields:

Caller User Name:-
Caller Domain:-
Caller Logon ID:-
Caller Process ID:-
Transited Services:-
Source Network Address:10.42.42.180
Source Port:0

Top 10 Windows Security Events to Monitor

Free Tool for Windows Event Collection



 

Upcoming Webinars
    Additional Resources

      Go To Event ID:

      Security Log
      Quick Reference
      Chart
      Download now!