0
i am seeing this error on 3 pcs on the network and on our server, they are coming from 1 account that has been deleted and 2 that are still on the PC's. we are on a regular workgroup network with 2012 server std. we have Changed everybody's passwords recently. No services are using any accounts with passwords we changed. i am seeing this event log every 15 minutes. There are many task's but i dont see any with the user that has been deleted or other 2 users. This has been driving me crazy and i have to disable our account lockout policy since it is locking out 2 accounts on the server side....Any help would be great!?
A logon was attempted using explicit credentials.
Subject: Security ID: NULL SID Account Name: - Account Domain: - Logon ID: 0x14CEB Logon GUID: {00000000-0000-0000-0000-000000000000}
Account Whose Credentials Were Used: Account Name: Melissa Account Domain: MELISSA-PC Logon GUID: {00000000-0000-0000-0000-000000000000}
Target Server: Target Server Name: SRV2008 Additional Information: SRV2008
Process Information: Process ID: 0x4 Process Name:
Network Information: Network Address: fe80::888:b5b0:27fb:13a0 Port: 445
This event is generated when a process attempts to log on an account by explicitly specifying that account’s credentials. This most commonly occurs in batch-type configurations such as scheduled tasks, or when using the RUNAS command.
I also checked the credential manager and no luck.. – Renho17 – 2017-08-02T23:44:37.317
Remove MELISSA-PC from the workgroup – Ramhound – 2017-08-02T23:45:25.353