Important Notice: On February 29th, this community was put into read-only mode. All existing posts will remain but customers are unable to add new posts or comment on existing. Please feel to join our Community Discord for any questions and discussions.

LAPS account logon failure for services.exe/advapi process during standard scan

We are noticing account logon failures (event id 4625) in the local security logs that is correlated with a PDQ Inventory standard scan as a LAPS user. The caller process name is C:\Windows\System32\services.exe and the status code is 0XC000015B - The user has not been granted the requested logon type (also called the logon right) at this machine. The logon process is Advapi. Subject account name is "computer$". Account for which logon failed is "Administrator". 

The PDQ Inventory standard scan completes successfully and returns no errors (we have previously configured AccountTokenFilterPolicy). The only reason we noticed this was because of a 4740 account lockout event for a domain account with the same name (that is disabled in our environment). The default name for the LAPS user account is Administrator (I've also tried with ".\Administrator" with same results - logon failure). 

I noticed that the logon failures (event id 4625) do not persist, if a machine is scanned repeatedly in rapid succession. So, this is somewhat of a non-issue for us but I'm still wondering if you have any insight into why this is happening. We have plans to test with a different default LAPS username to rule out the overlap between the local account username and the disabled default domain admin username.

0

Comments

2 comments
Date Votes