Server 2019 Event ID 1074, Reason Code: 0x50006 Lsass.exe terminated unexpectedly

TrungNV@HPT.VN 1 Reputation point
2021-07-05T05:03:44.72+00:00

The process wininit.exe has initiated the restart of computer Domain Controller 2019 on behalf of user for the following reason: No title for this reason could be found
Reason Code: 0x50006
Shutdown Type: restart
Comment: The system process 'C:\Windows\system32\lsass.exe' terminated unexpectedly with status code -1073740767. The system will now shut down and restart.

I detected that when I stop NETLOGON Services, server 2019 doesn't restart unexpectedly. But when start NETLOGON Services, it still restart every 5 ~ 10 minutes.

Windows Server 2019
Windows Server 2019
A Microsoft server operating system that supports enterprise-level management updated to data storage.
3,440 questions
{count} votes

5 answers

Sort by: Most helpful
  1. Eleven Yu (Shanghai Wicresoft Co,.Ltd.) 10,671 Reputation points Microsoft Vendor
    2021-07-05T07:53:45.673+00:00

    Hi,

    After researching, I found two threads mentioned the similar issue and contained possible solutions. But both of them were for Windows Server 2012 or 2012 R2.

    You can have a try on your windows server 2019.

    Solution 1: Increasing the MaxTempTableSize parameter value of LDAP

    Steps:

    1. Increase MaxTempTableSize up to a maximum of 100000 on the LDAP settings as per: https://support.microsoft.com/en-us/help/315071/how-to-view-and-set-ldap-policy-in-active-directory-by-using-ntdsutil
    2. Viewing current policy settings:
      a. At the Ntdsutil.exe command prompt, type LDAP policies, and then press ENTER.
      b. At the LDAP policy command prompt, type connections, and then press ENTER.
      c. At the server connection command prompt, type connect to server DNS name of server, and then press ENTER. You want to connect to the server that you are currently working with.
      d. At the server connection command prompt, type q, and then press ENTER to return to the previous menu.
      e. At the LDAP policy command prompt, type Show Values, and then press ENTER.
    3. Modifying policy settings
      a. At the Ntdsutil.exe command prompt, type LDAP policies, and then press ENTER.
      b. At the LDAP policy command prompt, type Set setting to variable (For example: Set MaxTempTableSize to 100000), and then press ENTER.

    Solution 2: Renaming the lplogin.dll to lplogin.dll.bak in safe mode and uninstalling the LastPass application in normal boot.

    For your reference:
    https://social.technet.microsoft.com/Forums/en-US/1b2a7958-4ecc-4ea0-a107-f53d1bd9fd18/the-process-wininitexe-has-initiated-the-restart-of-computer-on-behalf-of-user-for-the-following?forum=winserver8gen
    https://serverfault.com/questions/788240/server-2012-stuck-in-a-reboot-loop-lsass-exe-failed

    Thanks,


    If the Answer is helpful, please click "Accept Answer" and upvote it. Thanks.

    1 person found this answer helpful.

  2. Eleven Yu (Shanghai Wicresoft Co,.Ltd.) 10,671 Reputation points Microsoft Vendor
    2021-07-05T09:45:44.13+00:00

    Hi,

    Please kindly run below commands to see if there is any file system error and fix it:

    sfc /scannow
    Dism /Online /Cleanup-Image /CheckHealth
    Dism /Online /Cleanup-Image /ScanHealth
    Dism /Online /Cleanup-Image /RestoreHealth

    Also, please ensure that the latest Windows Update has been installed on your server.

    Thanks,


    If the Answer is helpful, please click "Accept Answer" and upvote it. Thanks.


  3. Eleven Yu (Shanghai Wicresoft Co,.Ltd.) 10,671 Reputation points Microsoft Vendor
    2021-07-06T03:31:04.83+00:00

    Hi,

    Another thing we can try is to replace your verifier.dll file under C:\Windows\System32 on the problematic server with a .dll file copied from another good machine with same version.

    If it still does not help, you might need to collect procmon logs using Process Monitor for further troubleshooting.
    https://learn.microsoft.com/en-us/sysinternals/downloads/procmon

    Thanks,

    ----------

    If the Answer is helpful, please click "Accept Answer" and upvote it. Thanks.


  4. Eleven Yu (Shanghai Wicresoft Co,.Ltd.) 10,671 Reputation points Microsoft Vendor
    2021-07-07T04:24:12.133+00:00

    Hi,

    Please kindly read below articles about how to use procmon.
    https://support.sophos.com/support/s/article/KB-000034769?language=en_US
    https://kb.acronis.com/procmon

    As forum service does not support procmon logs analysis, we suggest thay you could contact Microsoft Customer Support and Services where more in-depth investigation can be done so that you would get a more satisfying explanation and solution to this issue.

    You may find phone number for your region accordingly from the link below:
    Global Customer Service phone numbers
    https://support.microsoft.com/en-us/help/4051701/global-customer-service-phone-numbers

    Thanks,


    If the Answer is helpful, please click "Accept Answer" and upvote it. Thanks.


  5. Wilson Unu 6 Reputation points
    2022-01-19T18:54:22.697+00:00

    Hi TrungNguyenVan-8319,

    In order for you to resolve this issues, you need to check the most recent "windows security update" , that was installed and uninstall it. "KB5009595, KB5008897" Please make sure to also uninstall those bolded KB I post in this answer. Once you uninstall them, your issues should be resolved!

    Please, mark it as answer if this resolve your issues.

    Thanks!

    0 comments No comments