|
jmatt001 -> failure audit every minute (1.Dec.2003 4:23:00 PM)
|
I have the following failure audit posted in our security event log every minute after adding Exchange 2003 to our domain:
Event Type: Failure Audit Event Source: Security Event Category: Directory Service Access Event ID: 565 Date: 11/25/2003 Time: 8:12:15 AM User: NSI\NSI-EXCHANGE$ Computer: NSISERV Description: Object Open: Object Server: DS Object Type: configuration Object Name: CN=Configuration,DC=nsi,DC=local New Handle ID: - Operation ID: {0,54801911} Process ID: 296 Primary User Name: NSISERV$ Primary Domain: NSI Primary Logon ID: (0x0,0x3E7) Client User Name: NSI-EXCHANGE$ Client Domain: NSI Client Logon ID: (0x0,0x36D88) Accesses Control Access Privileges -
Properties: DELETE READ_CONTROL WRITE_OWNER ACCESS_SYS_SEC MAX_ALLOWED %%7691 %%7692 %%7693 Manage Replication Topology
Cannot find anything matching on Microsoft KB. Any ideas?
Thank you! Jonathan
|
|
|
|