I'm getting the following warning every 2 minutes in the security log on my
W2000 DC. I'm pretty sure the warning is being generated by a connection on
of my users is making to a remote server to access email for another company
he works for. How can I get this warning to stop? I currently have GP set
to audit account logon events pass/failure and audit logon events
pass/failure (I'd like to keep these settings if possible). Here is the
warning message being generated:
Event Type: Failure Audit
Event Source: Security
Event Category: Account Logon
Event ID: 676
Date: 5/18/2006
Time: 11:04:25 AM
User: NT AUTHORITY\SYSTEM
Computer: (SERVER NAME)
Description:
Authentication Ticket Request Failed:
User Name: username@remotedomain.com
Supplied Realm Name: OUR DOMAIN.COM
Service Name: krbtgt/OUR DOMAIN.COM
Ticket Options: 0x40810010
Failure Code: 0x6
Client Address: 192.168.221.17