It is worth checking these repair ideas if you get Security Event ID 529 error when entering type 10.
Approved: Fortect
g.
Connection range 10: RemoteInteractive. A user who is logged on to this computer remotely by using Terminal Services or Remote Desktop. This connection type is similar to two or three (interactive), but the user connects to a private connection from a remote computer via RDP (using Remote Desktop, Terminal Services, and also Remote Assistance).
g.
These could be “users” trying to log in with a new invalid user / password combination. the connection type indicates that “user” is trying to contact a resource or service that is shared in some (for example, a network share). Make sure to check the process id (PID) in Task Manager on the web server to see which service is in use.
Such unsuccessful attempts are common, should and should not pose a real direct security threat with a well-optimized password policy (except for users who actually cannot register / use Entwork resources because their account is locked out).
BUT … if this happens frequently, you should ask yourself if this is still possible due to the fact that your users are on the other side of multiple computers (which are not domainnames on the market) use unethical credentials to do it anyway; usually displayed because the username and The name of the computer is “Reality”. Instead, it could also be a brute force attack carried out on the client computer during malware, also known as attempting to infiltrate your network while the computer is connected to the Internet.
What is Event ID 4738?
Event 4738 was generated whenever a custom target was changed. Sometimes this event can indicate no change, that is, all changed attributes are displayed as “-“. This most often happens when a change is made to an attribute that is not listed with the event, in which case there is no way to know which attribute was previously changed.
Check the computer name for malware and / or cached credentials. If the server is connected to the Internet, your firewall settings.
There are some really good blogs out there that have articles on fully troubleshooting connectivity issues (but I’d say you look at client computers first).
http://blogs.msdn.com/b/spatdsg/archive/2005/12/23/507103.aspx
http://blogs.msdn.com/b/puneetgupta/archive/2007/08/20/unknown-username-or-bad-password-inetinfo-exe-advapi.aspx
What is Substatus code 0xC0000064?
Error Information Substate 0xC0000064 – “User login with an error or invalid account.”
Also see related topics on the right; many solved which contain helpful solutions or troubleshooting!
MCP / MCSA / MCTS / MCITP
- Edited byher SenneVL May 21, 2013 20:17
- The same answer is marked with æœ ± é¸¿æ– ‡ 28 May 2013, Tuesday, 2:14
These are “users” trying to log in with an invalid user / password combination. logon type indicates the type of “user” who is trying to use a shared resource service on the network (for example, a full file share on the network). Check Process ID (PID) in A business manager on your server to possibly identify the cloud that is in use.
What is the security ID for the logon event?
Introduction. Event ID 4624 (displayed when Windows Event Viewer is displayed) documents each successful attempt to connect to a nearby computer. This event is generated at the top of the accessed computer on which the connection class was created. A related event, Event ID 4625, documents failed login attempts.
Such unsuccessful attempts are widespread and, together with a well-tuned password policy, do not pose a direct security threat (except for users who cannot use / use resources in Entwork because their account is locked out).
What is the security ID for the logon event?
Introduction. Event ID 4624 (displayed in Windows Event Viewer) documents each successful write attempt on the local computer. This entry is created on the computer that was accessed for the first time, that is, on which the logon session was created. A related event, Event ID 4625, documents failed connection attempts.
BUT … if it is As this happens frequently, find out if the credentials of your users or multiple computers (that have not yet joined the domain) may be configured incorrectly. like, like, something like; mainly because the username and The name of the computer is “Reality”. Instead, it could be a full brute force attack performed by malware on each client computer, or, if the machine is now connected to the Internet, an attempt to infiltrate your network.
Check the name of the electronic computer for malware and / or check the cached credentials. If the server is connected to the Internet, check the policy settings.
Approved: Fortect
Fortect is the world's most popular and effective PC repair tool. It is trusted by millions of people to keep their systems running fast, smooth, and error-free. With its simple user interface and powerful scanning engine, Fortect quickly finds and fixes a broad range of Windows problems - from system instability and security issues to memory management and performance bottlenecks.
There are some good blog posts that regularly do detailed troubleshooting of connectivity issues (but I still suggest checking the client computer first).
What is logon type 10?
Breed registration dog 10: Remote Interactive. A user who is logged on to help you remotely on this computer using Terminal Services combined with Remote Desktop. This logon type is 2 (interactive), but the user logs on from a remote computer (from tothe power of Remote Desktop, Terminal Services, or Remote Support) because of RDP.
Just look at related topics with your right hand; There are many reliable solutions that have good solutions or troubleshooting information!
- Edited by SenneVL May 21, 2013 20:17
- Marked as a response by user æœ ± é¸¿æ– ‡ May 28, 2013 2:14 am