Guest chris Posted April 4, 2008 Posted April 4, 2008 The problem: A Microsoft Windows Server 2003-based member computer is joined to a domain controller. In the member server, the audit policy is turned on for logon failures. When a local user on the member computer logs off, the following event is logged in the Security log. Event Type: Failure Audit Event Source: Security Event Category: Logon/Logoff Event ID: 529 Date: date Time: time User: NT AUTHORITY\SYSTEM Computer: domain controller computer name Description: Logon Failure: Reason: Unknown user name or bad password User Name: user name Domain: client computer name Logon Type: 3 Logon Process: NtLmSsp Authentication Package: NTLM Workstation Name: client computer name For more information, see Help and Support Center at http://support.microsoft.com. I have found this error in KB article 811082 which has a Hotfix to resolve it. I tried to install it and receive a message that says the service pack level installed is newer then the Hot Fix. I am still receiving the error and it is becoming a large problem since I have hundreds of these failed audits a day. I can not turn off auditing on the server since it is a requirement.
Recommended Posts