Failure Audit "Security", "Directory Service Access", "565" on DC

Failure Audit "Security", "Directory Service Access", "565" on DC

Post by Garth » Thu, 02 May 2002 23:10:42



I recently demoted the E2K server to member server status after migrating
all of the FSMO roles to other DCs. Now I am getting the following event log
entry, one per minute, on the other DCs. Process ID# 260 is LSASS.

What's up?

Thanx,
Garth

Object Open:

Object Server: DS

Object Type: configuration

Object Name: CN=Configuration,DC=<domainname>,DC=com

New Handle ID: -

Operation ID: {0,108845}

Process ID: 260

Primary User Name: TTDC2$

Primary Domain: <domainname>

Primary Logon ID: (0x0,0x3E7)

Client User Name: <E2KServername$

Client Domain: <domain name>

Client Logon ID: (0x0,0x1A921)

Accesses Control Access

Privileges -

Properties:

READ_CONTROL

Create Child

Delete Child

List Contents

Write Self

Delete Tree

Manage Replication Topology