Answer the question
In order to leave comments, you need to log in
How to understand what and where blocks UZ in the domain?
Good morning! Periodically, something blocks the UZ in the domain, because of this, backup on the servers fails. How to understand what and where blocks UZ in the domain? The audit shows only such an event, but nothing is clear from it:
- <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
- <System>
<Provider Name="Microsoft-Windows-Security-Auditing" Guid="{54849625-5478-4994-A5BA-3E3B0328C30D}" />
<EventID>4740</EventID>
<Version>0</Version>
<Level>0</Level>
<Task>13824</Task>
<Opcode>0</Opcode>
<Keywords>0x8020000000000000</Keywords>
<TimeCreated SystemTime="2018-10-07T02:09:45.330890800Z" />
<EventRecordID>5750135</EventRecordID>
<Correlation />
<Execution ProcessID="584" ThreadID="624" />
<Channel>Security</Channel>
<Computer>wsdc-01.domen.local</Computer>
<Security />
</System>
- <EventData>
<Data Name="TargetUserName">backup</Data>
<Data Name="TargetDomainName" />
<Data Name="TargetSid">S-1-5-21-3362886647-1212668267-832902950-11833</Data>
<Data Name="SubjectUserSid">S-1-5-18</Data>
<Data Name="SubjectUserName">WSDC-01$</Data>
<Data Name="SubjectDomainName">domen.local</Data>
<Data Name="SubjectLogonId">0x3e7</Data>
</EventData>
</Event>
Answer the question
In order to leave comments, you need to log in
Didn't find what you were looking for?
Ask your questionAsk a Question
731 491 924 answers to any question