Windows Vista Tips

Windows Vista Tips > Newsgroups > Windows Server > Active Directory > New account cannot log in

Reply
Thread Tools Display Modes

New account cannot log in

 
 
Roger
Guest
Posts: n/a

 
      06-29-2010
I have a new Windows Server R2 domain set up.

The servers are in a remote location and are entirely managed and run via
Remote desktop.

My own account is a Domain admin account, I can log in remotely and manage
the Domain.

I am trying to create NEW accounts that can log in, but I consistantly get
an error like below, I am at a loss, the usernames and passwords DO exist
and we are typing them correctly. This affects new accounts only for some
reason.

Unknown username or bad password:

Log Name: Security
Source: Microsoft-Windows-Security-Auditing
Date: 6/29/2010 2:57:47 PM
Event ID: 4625
Task Category: Logon
Level: Information
Keywords: Audit Failure
User: N/A
Computer: DC1.vnet.corp
Description:
An account failed to log on.

Subject:
Security ID: SYSTEM
Account Name: DC1$
Account Domain: VNET
Logon ID: 0x3e7

Logon Type: 10

Account For Which Logon Failed:
Security ID: NULL SID
Account Name: <acct changed for security>
Account Domain: VNET.CORP

Failure Information:
Failure Reason: Unknown user name or bad password.
Status: 0xc000006d
Sub Status: 0xc000006a

Process Information:
Caller Process ID: 0xefc
Caller Process Name: C:\Windows\System32\winlogon.exe

Network Information:
Workstation Name: DC1
Source Network Address: 10.10.11.36
Source Port: 1413

Detailed Authentication Information:
Logon Process: User32
Authentication Package: Negotiate
Transited Services: -
Package Name (NTLM only): -
Key Length: 0

This event is generated when a logon request fails. It is generated on the
computer where access was attempted.

The Subject fields indicate the account on the local system which requested
the logon. This is most commonly a service such as the Server service, or a
local process such as Winlogon.exe or Services.exe.

The Logon Type field indicates the kind of logon that was requested. The
most common types are 2 (interactive) and 3 (network).

The Process Information fields indicate which account and process on the
system requested the logon.

The Network Information fields indicate where a remote logon request
originated. Workstation name is not always available and may be left blank
in some cases.

The authentication information fields provide detailed information about
this specific logon request.
- Transited services indicate which intermediate services have participated
in this logon request.
- Package name indicates which sub-protocol was used among the NTLM
protocols.
- Key length indicates the length of the generated session key. This will
be 0 if no session key was requested.
Event Xml:
<Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
<System>
<Provider Name="Microsoft-Windows-Security-Auditing"
Guid="{54849625-5478-4994-A5BA-3E3B0328C30D}" />
<EventID>4625</EventID>
<Version>0</Version>
<Level>0</Level>
<Task>12544</Task>
<Opcode>0</Opcode>
<Keywords>0x8010000000000000</Keywords>
<TimeCreated SystemTime="2010-06-29T18:57:47.614777300Z" />
<EventRecordID>7710090</EventRecordID>
<Correlation />
<Execution ProcessID="496" ThreadID="3532" />
<Channel>Security</Channel>
<Computer>DC1.vnet.corp</Computer>
<Security />
</System>
<EventData>
<Data Name="SubjectUserSid">S-1-5-18</Data>
<Data Name="SubjectUserName">DC1$</Data>
<Data Name="SubjectDomainName">VNET</Data>
<Data Name="SubjectLogonId">0x3e7</Data>
<Data Name="TargetUserSid">S-1-0-0</Data>
<Data Name="TargetUserName"><acct changed for security></Data>
<Data Name="TargetDomainName">VNET.CORP</Data>
<Data Name="Status">0xc000006d</Data>
<Data Name="FailureReason">%%2313</Data>
<Data Name="SubStatus">0xc000006a</Data>
<Data Name="LogonType">10</Data>
<Data Name="LogonProcessName">User32 </Data>
<Data Name="AuthenticationPackageName">Negotiate</Data>
<Data Name="WorkstationName">DC1</Data>
<Data Name="TransmittedServices">-</Data>
<Data Name="LmPackageName">-</Data>
<Data Name="KeyLength">0</Data>
<Data Name="ProcessId">0xefc</Data>
<Data Name="ProcessName">C:\Windows\System32\winlogon.ex e</Data>
<Data Name="IpAddress">10.10.11.36</Data>
<Data Name="IpPort">1413</Data>
</EventData>
</Event>


 
Reply With Quote
 
 
 
 
Roger
Guest
Posts: n/a

 
      06-29-2010
Solved.

I was attempting to create a new domain admin user while logged in as me,
Domain admin and schema admin. The account was created successfully, I could
assign the account to the groups successfully, all looked fine, but of
course the user could not log in.

I logged in as the built in Administrator account and created the same
account using the same methods, assigned to the same groups and they can now
log in.

It appears that even though I (as me) am allowed to complete all the actions
to create a new domain admin, and the os reports no errors warnings or
problems, I really can't. Windows just isn't going to tell me I can't. It's
going to let me believe it worked, when it didn't.

"Roger" <> wrote in message
news:...
>I have a new Windows Server R2 domain set up.
>
> The servers are in a remote location and are entirely managed and run via
> Remote desktop.
>
> My own account is a Domain admin account, I can log in remotely and manage
> the Domain.
>
> I am trying to create NEW accounts that can log in, but I consistantly get
> an error like below, I am at a loss, the usernames and passwords DO exist
> and we are typing them correctly. This affects new accounts only for some
> reason.
>
> Unknown username or bad password:
>
> Log Name: Security
> Source: Microsoft-Windows-Security-Auditing
> Date: 6/29/2010 2:57:47 PM
> Event ID: 4625
> Task Category: Logon
> Level: Information
> Keywords: Audit Failure
> User: N/A
> Computer: DC1.vnet.corp
> Description:
> An account failed to log on.
>
> Subject:
> Security ID: SYSTEM
> Account Name: DC1$
> Account Domain: VNET
> Logon ID: 0x3e7
>
> Logon Type: 10
>
> Account For Which Logon Failed:
> Security ID: NULL SID
> Account Name: <acct changed for security>
> Account Domain: VNET.CORP
>
> Failure Information:
> Failure Reason: Unknown user name or bad password.
> Status: 0xc000006d
> Sub Status: 0xc000006a
>
> Process Information:
> Caller Process ID: 0xefc
> Caller Process Name: C:\Windows\System32\winlogon.exe
>
> Network Information:
> Workstation Name: DC1
> Source Network Address: 10.10.11.36
> Source Port: 1413
>
> Detailed Authentication Information:
> Logon Process: User32
> Authentication Package: Negotiate
> Transited Services: -
> Package Name (NTLM only): -
> Key Length: 0
>
> This event is generated when a logon request fails. It is generated on the
> computer where access was attempted.
>
> The Subject fields indicate the account on the local system which
> requested the logon. This is most commonly a service such as the Server
> service, or a local process such as Winlogon.exe or Services.exe.
>
> The Logon Type field indicates the kind of logon that was requested. The
> most common types are 2 (interactive) and 3 (network).
>
> The Process Information fields indicate which account and process on the
> system requested the logon.
>
> The Network Information fields indicate where a remote logon request
> originated. Workstation name is not always available and may be left blank
> in some cases.
>
> The authentication information fields provide detailed information about
> this specific logon request.
> - Transited services indicate which intermediate services have
> participated in this logon request.
> - Package name indicates which sub-protocol was used among the NTLM
> protocols.
> - Key length indicates the length of the generated session key. This will
> be 0 if no session key was requested.
> Event Xml:
> <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
> <System>
> <Provider Name="Microsoft-Windows-Security-Auditing"
> Guid="{54849625-5478-4994-A5BA-3E3B0328C30D}" />
> <EventID>4625</EventID>
> <Version>0</Version>
> <Level>0</Level>
> <Task>12544</Task>
> <Opcode>0</Opcode>
> <Keywords>0x8010000000000000</Keywords>
> <TimeCreated SystemTime="2010-06-29T18:57:47.614777300Z" />
> <EventRecordID>7710090</EventRecordID>
> <Correlation />
> <Execution ProcessID="496" ThreadID="3532" />
> <Channel>Security</Channel>
> <Computer>DC1.vnet.corp</Computer>
> <Security />
> </System>
> <EventData>
> <Data Name="SubjectUserSid">S-1-5-18</Data>
> <Data Name="SubjectUserName">DC1$</Data>
> <Data Name="SubjectDomainName">VNET</Data>
> <Data Name="SubjectLogonId">0x3e7</Data>
> <Data Name="TargetUserSid">S-1-0-0</Data>
> <Data Name="TargetUserName"><acct changed for security></Data>
> <Data Name="TargetDomainName">VNET.CORP</Data>
> <Data Name="Status">0xc000006d</Data>
> <Data Name="FailureReason">%%2313</Data>
> <Data Name="SubStatus">0xc000006a</Data>
> <Data Name="LogonType">10</Data>
> <Data Name="LogonProcessName">User32 </Data>
> <Data Name="AuthenticationPackageName">Negotiate</Data>
> <Data Name="WorkstationName">DC1</Data>
> <Data Name="TransmittedServices">-</Data>
> <Data Name="LmPackageName">-</Data>
> <Data Name="KeyLength">0</Data>
> <Data Name="ProcessId">0xefc</Data>
> <Data Name="ProcessName">C:\Windows\System32\winlogon.ex e</Data>
> <Data Name="IpAddress">10.10.11.36</Data>
> <Data Name="IpPort">1413</Data>
> </EventData>
> </Event>
>



 
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are Off


Similar Threads
Thread Thread Starter Forum Replies Last Post
messengeruser account password grovelli Windows Live Messenger 10 05-05-2010 05:25 PM
0x8BAD0008 Greg Just Windows Live Mail 1 03-24-2010 07:54 AM
Did you ever find out what was locking the account? Joe Glim Active Directory 6 01-11-2010 08:18 PM
Unable to add computer to domain Nik Active Directory 5 12-18-2009 08:29 PM
Rename Accounts Dave Windows Vista Administration 4 06-29-2007 04:56 PM



1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59