Quantcast
Viewing all articles
Browse latest Browse all 31638

User Account is getting locked with NETBIOS_HOSTNAME as source computer name. Event ID 4776

Hi Gurus,

one of our Users is getting locked every day between 07:30-08:30. If we analyze the netlogon or security events on the DC we can see that the following event are registered.

4776,AUDIT FAILURE,Microsoft-Windows-Security-Auditing,Thu May 23 08:08:27 2013,No User,The computer attempted to validate the credentials for an account.   Authentication Package: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0  Logon Account: ikesken  Source Workstation: NETBIOS_HOSTNAME Error Code: 0xc0000234 

05/24 08:11:19 [LOGON] VFTR: SamLogon: Transitive Network logon of VFTR\ikesken from NETBIOS_HOSTNAME (via NSI) Returns 0xC000006A

The problem is that there isn't any Workstation in our network named netbios_hostname. Does someone know how to find that workstation ? Any ideas or hints ?

I appreciate your help.

Kind regards,

Cengiz Kuskaya







Viewing all articles
Browse latest Browse all 31638

Trending Articles