Quantcast
Viewing all articles
Browse latest Browse all 26374

SharePoint 2013 Farm Administrator multiple Audit Failure on Domain Controller

We have built a test Sharepoint 2013 site, and while looking at our Security Logs on our Domain controller, I noticed thousands of these errors, they all correlate to the farm administrator for our SharePoint farm. (Which is why I'm posting it here and not another forum.) Has anyone seen these before? Have a solution to why this is happeneing?

Log Name:      Security
Source:        Microsoft-Windows-Security-Auditing
Date:          8/30/2013 2:57:09 PM
Event ID:      4769
Task Category: Kerberos Service Ticket Operations
Level:         Information
Keywords:      Audit Failure
User:          N/A
Computer:      xxx.yyyy.com
Description:
A Kerberos service ticket was requested.

Account Information:
 Account Name:  sharepointadmin@domain.com
 Account Domain:  DOMAIN.COM
 Logon GUID:  {00000000-0000-0000-0000-000000000000}

Service Information:
 Service Name:  sharepointadmin
 Service ID:  NULL SID

Network Information:
 Client Address:  ::ffff:10.xx.xx.xx
 Client Port:  56600

Additional Information:
 Ticket Options:  0x40810000
 Ticket Encryption Type: 0xffffffff
 Failure Code:  0x1b
 Transited Services: -

This event is generated every time access is requested to a resource such as a computer or a Windows service.  The service name indicates the resource to which access was requested.

This event can be correlated with Windows logon events by comparing the Logon GUID fields in each event.  The logon event occurs on the machine that was accessed, which is often a different machine than the domain controller which issued the service ticket.

Ticket options, encryption types, and failure codes are defined in RFC 4120.
Event Xml:
<Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
  <System>
    <Provider Name="Microsoft-Windows-Security-Auditing" Guid="{54849625-5478-4994-A5BA-3E3B0328C30D}" />
    <EventID>4769</EventID>
    <Version>0</Version>
    <Level>0</Level>
    <Task>14337</Task>
    <Opcode>0</Opcode>
    <Keywords>0x8010000000000000</Keywords>
    <TimeCreated SystemTime="2013-08-30T18:57:09.092602500Z" />
    <EventRecordID>35980222</EventRecordID>
    <Correlation />
    <Execution ProcessID="464" ThreadID="1476" />
    <Channel>Security</Channel>
    <Computer>xxxx.yyyyy.com</Computer>
    <Security />
  </System>
  <EventData>
    <Data Name="TargetUserName">sharepointadmin@domain.com</Data>
    <Data Name="TargetDomainName">domain.com</Data>
    <Data Name="ServiceName">sharepointadmin</Data>
    <Data Name="ServiceSid">S-1-0-0</Data>
    <Data Name="TicketOptions">0x40810000</Data>
    <Data Name="TicketEncryptionType">0xffffffff</Data>
    <Data Name="IpAddress">::ffff:10.xxx.xxx.xxx</Data>
    <Data Name="IpPort">56600</Data>
    <Data Name="Status">0x1b</Data>
    <Data Name="LogonGuid">{00000000-0000-0000-0000-000000000000}</Data>
    <Data Name="TransmittedServices">-</Data>
  </EventData>
</Event>


Viewing all articles
Browse latest Browse all 26374

Trending Articles



<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>