数千个 4776 事件
我面临一个问题,导致 DC 上发生数千个成功的 4776 事件。我发现某种网络打印机枚举导致了它。例如,每次在word中刷新或打开打印机,都会触发大量4776。即使用户不使用计算机,因此计算机被锁定,也会发生这种情况。知道为什么会这样吗?我怀疑这是由于打开名为管道的打印机引起的,我在 ProcMon 创建、关闭 pipeline\spools 打印机路径上的文件中看到。服务器是W2K8 R2,客户端是W10
提前致谢
I'm facing a problem which causing thousands of successful 4776 events on DCs. I figured out that some kind of network printer enumeration causing it. Every refreshing or opening printers in word for example, triggers a lot of 4776. It takes place even when user doesn't use computer so it is locked. Any idea why it works like that? I suspect that it is caused by opening printer named pipe, I see in ProcMon create, close file on pipe\spools printer path. Server is W2K8 R2 , client W10
Thanks in advance
如果你对这篇内容有疑问,欢迎到本站社区发帖提问 参与讨论,获取更多帮助,或者扫码二维码加入 Web 技术交流群。
绑定邮箱获取回复消息
由于您还没有绑定你的真实邮箱,如果其他用户或者作者回复了您的评论,将不能在第一时间通知您!
发布评论
评论(1)
每次使用 NTLM 身份验证进行凭据验证时,通常都会出现此问题“数千个 4776 事件”。它显示成功和不成功的凭据验证尝试。
从 4776 事件日志中获取源工作站地址,请检查以下步骤:
参考文献:
4776 (S, F) 计算机尝试验证帐户的凭据。 (Windows 10) - Windows 安全 |微软文档。
事件 ID 4776 / 0xc00006a - Microsoft Q& ;A。
This problem "Thousands of 4776 events" usually occurs every time that a credential validation occurs using NTLM authentication. It shows successful and unsuccessful credential validation attempts.
Obtain the source workstation address from 4776 event log and please check below steps:
References:
4776(S, F) The computer attempted to validate the credentials for an account. (Windows 10) - Windows security | Microsoft Docs.
Event ID 4776 / 0xc00006a - Microsoft Q&A.