4625 Audit Failure events on Workgroup server when connecting to alocal share

Discussion in 'Security Software' started by BillL, Nov 11, 2010.

  1. BillL

    BillL Guest


    I have a Windows Server 2008 (with SP2 installed) machine in a
    workgroup. While logged onto the server with the local Administrator
    account if I attempt to connect to a share on this server by doing a
    Start -> Run \\Server\Share1, I am prompted for credentials and
    numerous 4625 Audit Failure messages are generated in the Security
    log. The messages have a Status code of 0xc000006d. The messages are
    generated before I attempt to respond to the prompt with credentials.
    If I do attempt to enter credentials, the logon is unsuccessful.

    If instead I do a Start -> Run \\localhost\Share1 then I am connected
    to the share with no credential prompt and no 4625 Audit Failure

    The 4625 events show a Security ID of NULL SID and the Authentication
    Package of NTLM even though the Local Security Policy - Network
    Security - LAN Manager Authentication Level is set to Send NTLMv2
    response only.

    Any ideas?

    BillL, Nov 11, 2010
    1. Advertisements

Ask a Question

Want to reply to this thread or ask your own question?

You'll need to choose a username for the site, which only take a couple of moments (here). After that, you can post your question and our members will help you out.