Windows 10: windows server 2012 Event id 4979 - An attempt was made to query the existence of a blank...

Discus and support windows server 2012 Event id 4979 - An attempt was made to query the existence of a blank... in AntiVirus, Firewalls and System Security to solve the problem; When I log in to the window server 2012. the account may trigger the server to query the existence of a blank password for all of the local account in... Discussion in 'AntiVirus, Firewalls and System Security' started by PeterFong3, Nov 11, 2020.

  1. windows server 2012 Event id 4979 - An attempt was made to query the existence of a blank...


    When I log in to the window server 2012. the account may trigger the server to query the existence of a blank password for all of the local account in the server Event ID 4979

    In the security event log, there will be a list of action logged to indicate that my account queried the existence of a blank password for all of the local account in the server.


    What are the causes to lead this abnormal action?


    As the query actions are not triggered every time when I log in the server. There is only some chances to trigger the action.

    What condition will trigger the account to query the existence of a blank password for all of the local account in the server ?


    Are there any security issues for the query action?


    Thanks.

    :)
     
    PeterFong3, Nov 11, 2020
    #1

  2. Security Audit Event ID 4797 "An attempt was made to query the existence of a blank password for an account"

    I'm currently parsing through event viewer on our devices and I've noticed a few cases of Event ID 4797, which states:

    An attempt was made to query the existence of a blank password for an account

    Could I get a little guidance on what this exactly means and a good course of action to take? What are the chances that some of these could be false positives?
     
    DaxTheBadger, Nov 11, 2020
    #2
  3. windows 10 event id 10 - An attempt was made to query the existence of a blank password for an account.

    Hello Steve,

    Security auditing is a powerful tool to help maintain the security of an enterprise. Auditing can be used for a variety of purposes, including forensic analysis, regulatory compliance, monitoring user activity, and troubleshooting. Industry regulations in
    various countries or regions require enterprises to implement a strict set of rules related to data security and privacy. Security audits can help implement such policies and prove that these policies have been implemented. Also, security auditing can be used
    for forensic analysis, to help administrators detect anomalous behavior, to identify and mitigate gaps in security policies, and to deter irresponsible behavior by tracking critical user activities. You can check this
    article for more information.

    Furthermore, you received this even when the Audit User Account Management
    is enabled, it generates audit events when specific user account management tasks are performed. The level of auditing is informational and not a warning or error. The said event is normal and can be safely ignored. The purpose is to check if by any chance
    a user is set for a Blank password so that users doesn't see a password box before they sign in when they have no password.

    Let me know if you have other concerns.

    Regards.
     
    Melchizedek Qui, Nov 11, 2020
    #3
  4. MargaFi Win User

    windows server 2012 Event id 4979 - An attempt was made to query the existence of a blank...

    Event ID 1 Event Record 94672 Source WSH on Windows Server 2012 R2

    I'm trying to find information on how to solve event viewer Event ID 1 Event Record 94672 Source WSH on Windows Server 2012 R2. I've not been able to find any pointers as to what is generating this error. This server is used as svn repo and when these
    event viewer error appears it refuses connections until the server is restarted. Any pointers will be appreciated. Thanks!
     
    MargaFi, Nov 11, 2020
    #4
Thema:

windows server 2012 Event id 4979 - An attempt was made to query the existence of a blank...

Loading...
  1. windows server 2012 Event id 4979 - An attempt was made to query the existence of a blank... - Similar Threads - server 2012 Event

  2. An attempt was made to reference a token that does not exist

    in Windows 10 Gaming
    An attempt was made to reference a token that does not exist: An attempt was made to reference a token that does not exist https://answers.microsoft.com/en-us/windows/forum/all/an-attempt-was-made-to-reference-a-token-that-does/a57ff71c-ab85-4d31-860a-cf8f90d12db5
  3. An attempt was made to reference a token that does not exist

    in Windows 10 Software and Apps
    An attempt was made to reference a token that does not exist: An attempt was made to reference a token that does not exist https://answers.microsoft.com/en-us/windows/forum/all/an-attempt-was-made-to-reference-a-token-that-does/a57ff71c-ab85-4d31-860a-cf8f90d12db5
  4. An attempt was made to reference a token that does not exist

    in Windows 10 Installation and Upgrade
    An attempt was made to reference a token that does not exist: An attempt was made to reference a token that does not exist https://answers.microsoft.com/en-us/windows/forum/all/an-attempt-was-made-to-reference-a-token-that-does/a57ff71c-ab85-4d31-860a-cf8f90d12db5
  5. Windows server 2012 R2 event ID 16385 error

    in Windows 10 Gaming
    Windows server 2012 R2 event ID 16385 error: - <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">- <System> <Provider Name="Microsoft-Windows-Security-SPP" Guid="{E23B33B0-C8C9-472C-A5F9-F2BDFEA0F156}" EventSourceName="Software Protection Platform Service" /> <EventID...
  6. Windows server 2012 R2 event ID 16385 error

    in Windows 10 Software and Apps
    Windows server 2012 R2 event ID 16385 error: - <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">- <System> <Provider Name="Microsoft-Windows-Security-SPP" Guid="{E23B33B0-C8C9-472C-A5F9-F2BDFEA0F156}" EventSourceName="Software Protection Platform Service" /> <EventID...
  7. Windows server 2012 R2 event ID 16385 error

    in Windows 10 BSOD Crashes and Debugging
    Windows server 2012 R2 event ID 16385 error: - <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">- <System> <Provider Name="Microsoft-Windows-Security-SPP" Guid="{E23B33B0-C8C9-472C-A5F9-F2BDFEA0F156}" EventSourceName="Software Protection Platform Service" /> <EventID...
  8. Event ID 10016 Fix Query

    in Windows 10 BSOD Crashes and Debugging
    Event ID 10016 Fix Query: Good day everyone, regarding to this Fix https://answers.microsoft.com/en-us/windows/forum/windows8_1-winapps/weather-application/e4630db3-50c2-4cc5-9813-f089494a1145 for Event ID 10016. I would like to ask the instruction on number 5, when it says to apply full...
  9. Security Audit Event ID 4797 "An attempt was made to query the existence of a blank...

    in AntiVirus, Firewalls and System Security
    Security Audit Event ID 4797 "An attempt was made to query the existence of a blank...: I'm currently parsing through event viewer on our devices and I've noticed a few cases of Event ID 4797, which states: An attempt was made to query the existence of a blank password for an account Could I get a little guidance on what this exactly means and a good course of...
  10. An attempt was made to reference a token that does not exist

    in Windows 10 News
    An attempt was made to reference a token that does not exist: [ATTACH] [ATTACH]If your Windows File Explorer has stopped working and you see an error while trying to open it – An attempt was made to reference a token that does not exist, then this post may be able to help you. [...] This post An attempt was made to reference a token...