Event ID for Machine went out of domain

suresh sundaram 1 Reputation point
2021-05-27T22:43:21.94+00:00

Have more than 4000 Desktop PCs in our environment. There are some machines going out of domain by automatically. Would like to get to know the Event ID when machine going out by automatically. It will be helpful to trace the machines through Splunk( Event Log)

Windows Server
Windows Server
A family of Microsoft server operating systems that support enterprise-level management, data storage, applications, and communications.
13,726 questions
{count} votes

4 answers

Sort by: Most helpful
  1. Anonymous
    2021-05-27T23:14:57.423+00:00

    Possibly netlogon source events in the System event log of IDs 5719, 5722 or 5723
    https://learn.microsoft.com/en-us/troubleshoot/windows-server/windows-security/secure-channel-problems-detected

    You could do nltest /sc_query:domainname to check

    --please don't forget to Accept as answer if the reply is helpful--

    0 comments No comments

  2. Fan Fan 15,366 Reputation points Microsoft External Staff
    2021-05-28T00:00:05.02+00:00

    Hi,

    It is suggested to enable the audit policies on DCs.
    The policy: Audit computer account management is under Computer Configuration\Windows Settings\Security Settings\Advanced audit policy\ Account management\Audit Computer account management
    100411-5282.jpg
    This policy setting allows you to audit events generated by changes to computer accounts such as when a computer account is created, changed, or deleted.

    Best Regards,

    0 comments No comments

  3. Anonymous
    2021-06-04T12:31:05.837+00:00

    Just checking if there's any progress or updates?

    --please don't forget to upvote and Accept as answer if the reply is helpful--

    0 comments No comments

  4. Shaikh, Iqbal 1 Reputation point
    2023-03-08T10:40:13.22+00:00

    we had similar scenarios, mostly it happens when staff reset passwords remotely using MFA via laptops and then they logon to the office with their old passwords

    the only way out is to have local admin account to reset their machine passwords

    it is a challenge if you have encrypted drives

    0 comments No comments

Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.