D
D
Dmitry Shumov2018-10-08 07:40:23
Active Directory
Dmitry Shumov, 2018-10-08 07:40:23

How to understand what and where blocks UZ in the domain?

Good morning! Periodically, something blocks the UZ in the domain, because of this, backup on the servers fails. How to understand what and where blocks UZ in the domain? The audit shows only such an event, but nothing is clear from it:

- <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
- <System>
  <Provider Name="Microsoft-Windows-Security-Auditing" Guid="{54849625-5478-4994-A5BA-3E3B0328C30D}" /> 
  <EventID>4740</EventID> 
  <Version>0</Version> 
  <Level>0</Level> 
  <Task>13824</Task> 
  <Opcode>0</Opcode> 
  <Keywords>0x8020000000000000</Keywords> 
  <TimeCreated SystemTime="2018-10-07T02:09:45.330890800Z" /> 
  <EventRecordID>5750135</EventRecordID> 
  <Correlation /> 
  <Execution ProcessID="584" ThreadID="624" /> 
  <Channel>Security</Channel> 
  <Computer>wsdc-01.domen.local</Computer> 
  <Security /> 
  </System>
- <EventData>
  <Data Name="TargetUserName">backup</Data> 
  <Data Name="TargetDomainName" /> 
  <Data Name="TargetSid">S-1-5-21-3362886647-1212668267-832902950-11833</Data> 
  <Data Name="SubjectUserSid">S-1-5-18</Data> 
  <Data Name="SubjectUserName">WSDC-01$</Data> 
  <Data Name="SubjectDomainName">domen.local</Data> 
  <Data Name="SubjectLogonId">0x3e7</Data> 
  </EventData>
  </Event>

Answer the question

In order to leave comments, you need to log in

Didn't find what you were looking for?

Ask your question

Ask a Question

731 491 924 answers to any question