Troubleshooting Security events in Server 2012

Mike Garczynski 1 Reputation point
2020-08-27T11:24:51.947+00:00

I am seeing alot of activity in the events log associated with the MSOL_xxxxx account especially off hours. Is this normal or should I be looking for a cause? The event logs samples are below.

Security: A Kerberos authentication ticket (TGT) was requested.
Security: A Kerberos service ticket was requested.
Security: A logon was attempted using explicit credentials.
Security: An account was successfully logged on.
Security: An account was logged off.
Security: A Kerberos authentication ticket (TGT) was requested.
Security: A Kerberos service ticket was requested.
Security: A logon was attempted using explicit credentials.
Security: An account was successfully logged on.
Security: An account was logged off.

Security: An account was successfully logged on.
Security: An operation was performed on an object.
Security: An operation was performed on an object.
Security: An operation was performed on an object.
Security: A Kerberos service ticket was requested.
Security: A logon was attempted using explicit credentials.
Security: An account was successfully logged on.
Security: An account was logged off.
Security: Special privileges assigned to new logon.
Security: An account was successfully logged on.
Security: An account was logged off.
Security: Special privileges assigned to new logon.
Security: An account was successfully logged on.

Windows for business | Windows Server | Devices and deployment | Configure application groups
0 comments No comments
{count} votes

1 answer

Sort by: Most helpful
  1. Anonymous
    2020-08-28T02:24:12.717+00:00

    Hello,

    Thank you so much for posting here.

    Once we configured these audit policies, there will be event logs recorded such as:

    Security: A Kerberos authentication ticket (TGT) was requested.
    Security: A logon was attempted using explicit credentials.
    Security: An account was successfully logged on.
    Security: An account was logged off.

    20988-2.png
    21005-3.png

    If lots of accounts log on, there will be lots of activities in the event logs. According to our description, all the event logs are associated with certain account. If we have any doubt, we could verity whether this account is real and existed and then contact the account MSOL_xxxxx account to verify whether this account has preformed the actions.

    For any question, please feel free to contact us.

    Best regards,
    Hannah Xiong


Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.