After loading the R2 Schema in our production forest, we are gettiing multiple Audit Failure 566 events from users and workstations against the unixUserPassword attrib on Users and Group objects. After we upgraded from 2000 to 2003, we have anonymous logon and everyone and auth users in our Pre-Windows 2000 compatible group. I have checked that one of the error generators has read access to the specific objext/attrib. It is happening in other or maybe all domains within our Forest. So does anyone has any ideas?
Event Type: Failure Audit
Event Source: Security
Event Category: Directory Service Access
Event ID: 566
Date: 24/11/2006
Time: 10:54:55
User: London Workstation$
Computer: Domain Controller$
Description:
Object Operation:
Object Server: DS
Operation Type: Object Access
Object Type: user
Object Name: CN=UserName,OU=Users,OU=LON,OU=Europe,DC=Our
Domain,DC=Our Company,DC=com
Handle ID: -
Primary User Name: Domain Controller$
Primary Domain: Our Domain
Primary Logon ID: (0x0,0x3E7)
Client User Name: London Workstation$
Client Domain: Our Domain
Client Logon ID: (0x1,0x51625D32)
Accesses: Control Access
Bookmarks