Windows 10: Domain administrator with several authentication attempts on DC

Discus and support Domain administrator with several authentication attempts on DC in AntiVirus, Firewalls and System Security to solve the problem; Hi,We have the "administrator" domain account disabled as the best practice says.I have 200k+ daily failed login attempts from that user from my domain... Discussion in 'AntiVirus, Firewalls and System Security' started by Rodrigo Catarino, May 18, 2023.

  1. Domain administrator with several authentication attempts on DC


    Hi,We have the "administrator" domain account disabled as the best practice says.I have 200k+ daily failed login attempts from that user from my domain controller to the same machine.The logon service attempt is from krbtgt/MYDOMAIN but as the account is disabled the authentication fails.How can i validate/correct this?Kind regards,Rodrigo Catarino

    :)
     
    Rodrigo Catarino, May 18, 2023
    #1

  2. Child Domain Controller logging 0xC0000064 for accounts attempting to authenticate from another child domain

    Dear All,

    I am trying to understand what are the factors that would cause event id 4776 to be logged with 0xC0000064 error code.

    The scenario is, several domain accounts say for example, accounts in child domain child1.example.com is trying to authenticate through child2.example.com but the DC in child2.example.com keeps the attempts failed indicating "User name does not exist".

    May I ask you to assist with info on how the authentication is expected to take place from one child domain to another child domain? Is it possible? If yes, how it works? More details would very helpful.

    If this is possible, what are the probable reasons behind a DC to be generating failure events with error code "User name does not exist". What could be done to fix these problems?

    Thanks for your support in advance.

    The DC is running Win 2012 R2 standard

    Regards,

    Madhan
     
    MadhanBabu, May 18, 2023
    #2
  3. changari Win User
    Raising the windows domain and forest issues?


    hi,

    I run a domain that was all 2003 r2 servers. I recently upgraded all my domain controllers to windows 2012 r2.
    That went off without any problems.. Our trust relationships had no issues also.

    My first step was to raise the Domain and Forest levels past 2003 to 2008. This went off without a hitch.
    These are the features for raising the levels to 2008:

    • Features and benefits include all default Active Directory features, all features from the Windows Server 2003 domain functional level, plus:
    • Read-Only Domain Controllers – Allows implementation of domain controllers that only host read-only copy of NTDS database.
    • Advanced Encryption Services – (AES 128 and 256) support for the Kerberos protocol.
    • Distributed File System Replication (DFSR) – Allows SYSVOL to replicate using DFSR instead of older File Replication Service (FRS). It provides more robust and detailed replication of SYSVOL contents.

    Forest Level Windows Server 2008

    • Features and benefits include all of the features that are available at the Windows Server 2003 forest functional level, but no additional features. All domains that are subsequently added to the forest will operate at the Windows Server 2008 domain functional level by default.


    My next step is to raise the domain and forest to 2008 r2, then 2012, and finally 2012 r2. I have been trying to find out exactly what I could expect from raising the Domain and Forest for each step.

    The step involving 2008 r2 seems relatively a non issue. But getting the couple of new features seem very nice

    Domain Level Windows Server 2008 R2

    • All default Active Directory features, all features from the Windows Server 2008 domain functional level, plus 2 new features

    Forest Level Windows Server 2008 R2

    • All of the features that are available at the Windows Server 2003 forest functional level, plus the following features:


    • Active Directory Recycle Bin, which provides the ability to restore deleted objects in their entirety while AD DS is running. <== New Feature very cool
    • All domains subsequently added to the forest will operate at the Windows Server 2008 R2 domain functional level by default.

    Here is my big concerns for the next raising of domain and forest to 2012.

    Forest Level Windows Server 2012:

    • All of the features that are available at the Windows Server 2008 R2 forest functional level, but no additional features.
    • All domains subsequently added to the forest will operate at the Windows Server 2012 domain functional level by default.

    Domain Level Windows Server 2012 R2: <=====
    Need to investigate more and why this post

    • DC-side protections for Protected Users. Protected Users authenticating to a Windows Server 2012 R2 domain can no longer:


    • Authenticate with NTLM authentication <==============(what issues may arise)
    • Use DES or RC4 cipher suites in Kerberos pre-authentication
    • Be delegated with unconstrained or constrained delegation
    • Renew user tickets (TGTs) beyond the initial 4-hour lifetime


    Will this affect my exchange anywhere users with remote access authenticating either clear of NTLM???
    and what would/may not to work properly day 1 when I raise the domain and forest to 2012. I cant really find anyone that can answer a straight question.

    Has anyone gone through this? what problems did you have, if any , if a lot???

    Any thoughts and suggestions will be much appreciated??

    thanks


    - - - Updated - - -

    One more point... I am not sure if I posted this to the correct forum.. So if I was wrong and it should be in a different one..
    PLEASE LET ME KNOW
     
    changari, May 18, 2023
    #3
  4. bdanmo Win User

    Domain administrator with several authentication attempts on DC

    UnattendedJoin error: failed to find the domain data (0x6e)

    Thanks for the suggestion! I don't want to add a domain account, as this is a generic unattended install that will be used for all company machines. Do you think it's possible that the computer would join the domain if, instead of using UnattendedJoin in specialize, I used your steps but left out the specific account?

    The other thing I was thinking was to use a generic account to allow the domain join during the specialize step. I added a machine password in the UnattendedJoin component, and instead of getting the error listed above, I got an authentication error, which makes me think I could probably do a secure join instead of the unsecure join.

    Thoughts?
     
    bdanmo, May 18, 2023
    #4
Thema:

Domain administrator with several authentication attempts on DC

Loading...
  1. Domain administrator with several authentication attempts on DC - Similar Threads - Domain administrator several

  2. Several Unknown Login Attempts

    in Windows 10 Software and Apps
    Several Unknown Login Attempts: I've been getting several Microsoft "single use code" emails off and on since Jan 21st., and checked my security info. I noticed failed several attempts to the tune of every couple minutes for several hours involving a "incorrect password" and they were all associated with...
  3. Authenticate with authenticator, approve your authenticator login attempt on your authenticator

    in Windows 10 Gaming
    Authenticate with authenticator, approve your authenticator login attempt on your authenticator: Why for the love of God do I have to wait 30 days just to change my phone number? Are identity thieves proven to be impatient and give up after 30days? This is some apple level nonsense. I know my password. I'm logged in. I use this device everyday. Authenticate with...
  4. Authenticate with authenticator, approve your authenticator login attempt on your authenticator

    in Windows 10 Software and Apps
    Authenticate with authenticator, approve your authenticator login attempt on your authenticator: Why for the love of God do I have to wait 30 days just to change my phone number? Are identity thieves proven to be impatient and give up after 30days? This is some apple level nonsense. I know my password. I'm logged in. I use this device everyday. Authenticate with...
  5. Domain administrator with several authentication attempts on DC

    in Windows 10 Gaming
    Domain administrator with several authentication attempts on DC: Hi,We have the "administrator" domain account disabled as the best practice says.I have 200k+ daily failed login attempts from that user from my domain controller to the same machine.The logon service attempt is from krbtgt/MYDOMAIN but as the account is disabled the...
  6. Domain administrator with several authentication attempts on DC

    in Windows 10 Software and Apps
    Domain administrator with several authentication attempts on DC: Hi,We have the "administrator" domain account disabled as the best practice says.I have 200k+ daily failed login attempts from that user from my domain controller to the same machine.The logon service attempt is from krbtgt/MYDOMAIN but as the account is disabled the...
  7. An Active Directory Domain Controller (AD DC) for the domain could not be contacted

    in Windows 10 News
    An Active Directory Domain Controller (AD DC) for the domain could not be contacted: [IMG]While connecting to a domain or changing the computer name, if you are getting An Active Directory Domain Controller (AD DC) for the domain “domain-name.com” could not be contacted error, here are some troubleshooting tips and tricks to fix this issue. It may appear due...
  8. Unable to authenticate as administrator, multiple devices, multiple clients, domain and non...

    in Windows 10 BSOD Crashes and Debugging
    Unable to authenticate as administrator, multiple devices, multiple clients, domain and non...: Hi All, First time posting here, but though as there is absolutely no information from Microsoft and seems like no other forums have picked up on this I will tell you a story about my frustration. Summery is below if you don't want to read it all. We started getting...
  9. Administrator in domain

    in Windows 10 Network and Sharing
    Administrator in domain: Greeting, A domain has been created in my company. I wonder if the domain administrator can see all the files on other computers even though they are not shared?Thanks....
  10. Authentication to domain without joining

    in Windows 10 Network and Sharing
    Authentication to domain without joining: as my subjects states I am looking to see if it is possible to Authenticate to a domain without joining. I am looking to be able to use my surface pro 4 device at some of our clients without having to join my device to any domain. even at my shop. where I could use one of...