authentication - An account failed to log on by C:\Windows\System32\inetsrv\appcmd.exe -
my domain account got locked many times each day. account team told me locked on server managed. after check security event log(windows server). got below detail information. still don't know program , when called. cannot remove appcmd.exe directly used iis , website host on it. i've searched , got many similar topics through internet. there no solution me. can me on question? thank in advance!
log detail:
an account failed log on. subject: security id: system account name: server1$ account domain: domain1 logon id: 0x3e7 logon type: 8 account logon failed: security id: null sid account name: ntaccount1 account domain: domain1 failure information: failure reason: unknown user name or bad password. status: 0xc000006d sub status: 0xc000006a process information: caller process id: 0x1ff0 caller process name: c:\windows\system32\inetsrv\appcmd.exe network information: workstation name: server1 source network address: - source port: - detailed authentication information: logon process: advapi authentication package: negotiate transited services: - package name (ntlm only): - key length: 0 event generated when logon request fails. generated on computer access attempted. subject fields indicate account on local system requested logon. commonly service such server service, or local process such winlogon.exe or services.exe. logon type field indicates kind of logon requested. common types 2 (interactive) , 3 (network). process information fields indicate account , process on system requested logon. network information fields indicate remote logon request originated. workstation name not available , may left blank in cases. authentication information fields provide detailed information specific logon request. - transited services indicate intermediate services have participated in logon request. - package name indicates sub-protocol used among ntlm protocols. - key length indicates length of generated session key. 0 if no session key requested.
Comments
Post a Comment