Velvet Star Monitor

Standout celebrity highlights with iconic style.

updates

A logon was attempted using explicit credentials. event ID 4648

Writer Mia Lopez

i am seeing this error on 3 pcs on the network and on our server, they are coming from 1 account that has been deleted and 2 that are still on the PC's. we are on a regular workgroup network with 2012 server std. we have Changed everybody's passwords recently. No services are using any accounts with passwords we changed. i am seeing this event log every 15 minutes. There are many task's but i dont see any with the user that has been deleted or other 2 users. This has been driving me crazy and i have to disable our account lockout policy since it is locking out 2 accounts on the server side....Any help would be great!?

A logon was attempted using explicit credentials.

Subject: Security ID: NULL SID Account Name: - Account Domain: - Logon ID: 0x14CEB Logon GUID: {00000000-0000-0000-0000-000000000000}

Account Whose Credentials Were Used: Account Name: Melissa Account Domain: MELISSA-PC Logon GUID: {00000000-0000-0000-0000-000000000000}

Target Server: Target Server Name: SRV2008 Additional Information: SRV2008

Process Information: Process ID: 0x4 Process Name:

Network Information: Network Address: fe80::888:b5b0:27fb:13a0 Port: 445

This event is generated when a process attempts to log on an account by explicitly specifying that account’s credentials. This most commonly occurs in batch-type configurations such as scheduled tasks, or when using the RUNAS command.

2 Reset to default

Know someone who can answer? Share a link to this question via email, Twitter, or Facebook.

Your Answer

Sign up or log in

Sign up using Google Sign up using Facebook Sign up using Email and Password

Post as a guest

By clicking “Post Your Answer”, you agree to our terms of service, privacy policy and cookie policy