Hi!
We use Exchange 2016 with latest updates and mostly Outlook 2016 clients.
Every time Outlook starts on non-domain computer it tries to authenticate several times on Exchange server with LOCAL user account (some of my users work on non-domain computers). But Outlook actually works fine. Have no idea why does it try to authenticate with Local username. I have checked that users have no wrong usernames and passwords saved in credentials manager.
I can see 4625 and 4776 Events in Audit failure logs on Exchange server.
4625 Example:
An account failed to log on.
Subject:
Security ID: NULL SID
Account Name: -
Account Domain: -
Logon ID: 0x0
Logon Type: 3
Account For Which Logon Failed:
Security ID: NULL SID
Account Name: <user name>
Account Domain: .
Failure Information:
Failure Reason: Unknown user name or bad password.
Status: 0xC000006D
Sub Status: 0xC0000064
Process Information:
Caller Process ID: 0x0
Caller Process Name: -
Network Information:
Workstation Name: DESKTOP-XXXXXX
Source Network Address: 111.111.111.111
Source Port: 2605
Detailed Authentication Information:
Logon Process: NtLmSsp
Authentication Package: NTLM
Transited Services: -
Package Name (NTLM only): -
Key Length: 0
4776 example:
The computer attempted to validate the credentials for an account.
Authentication Package: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0
Logon Account: <user name>
Source Workstation: DESKTOP-XXXXXX
Error Code: 0xC0000064
I'm using IPBan software and those attempts cause legal ip addresses blockings.
Can anyone help?