nicholab Posted June 5, 2019 Posted June 5, 2019 Issues with machine having logon form Administrator that get picked up by PA. Does anyone know why you get random logon form the Administrator on windows? An account was successfully logged on. Subject: Security ID: NULL SID Account Name: - Account Domain: - Logon ID: 0x0 Logon Information: Logon Type: 3 Restricted Admin Mode: - Virtual Account: No Elevated Token: Yes Impersonation Level: Impersonation New Logon: Security ID: domain\Administrator Account Name: Administrator Account Domain: domain.LOCAL Logon ID: 0x15C48486 Linked Logon ID: 0x0 Network Account Name: - Network Account Domain: - Logon GUID: {d9bda221-3421-6071-eaea-e9f8d871954d}
QwertyMash Posted June 6, 2019 Posted June 6, 2019 The logon type 3 is a network logon, so stuff like connecting to a shared folder on that machine from another device on the network or similar tasks. I believe WMI queries in some instances when done across a network can also result in a similar or the same log being made.
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now