1 Reply Latest reply on Oct 30, 2015 4:25 PM by kellytice

    WSUS using datagrid service account when accessing target managed PC.

    mrcoffeefreak

      Tasks that are scheduled and new update management tasks that are created are trying to attach to the target using the local datagrid service account. The correct credentials are in the credential ring and have been working for a couple years now. The only recent change is we added patch manager to our Orion interface.

       

      On the WSUS server I see:

      Exception occurred at 10/27/2015 1:00:05 AM. The transaction with Task ID: 59eedb25-03aa-4990-9da1-d72a266f1e2d and job ID: 1 and Scope: 123.mydomain.com appears to have stopped responding and was terminated at 10/27/2015 1:00:05 AM

       

      On the target PC I see:

      Event Type: Failure Audit

      Event Source: Microsoft-Windows-Security-Auditing

      Event Category: (12544)

      Event ID: 4625

      Date: 10/27/2015

      Time: 1:00:05 AM

      User: N/A

      Computer: 123.mydomain.com

      Description:

      An account failed to log on.

       

      Subject:

      Security ID: S-1-0-0

      Account Name: -

      Account Domain: -

      Logon ID: 0x0

       

      Logon Type: 3

       

      Account For Which Logon Failed:

      Security ID: S-1-0-0

      Account Name: ewdgssvc-17192

      Account Domain: WSUS

       

      Failure Information:

      Failure Reason: %%2313

      Status: 0xc000006d

      Sub Status: 0xc0000064

       

      Process Information:

      Caller Process ID: 0x0

      Caller Process Name: -

       

      Network Information:

      Workstation Name: WSUS

      Source Network Address: 10.64.x.xxx

      Source Port: 51272

       

      Detailed Authentication Information:

      Logon Process: NtLmSsp

      Authentication Package: NTLM

      Transited Services: -

      Package Name (NTLM only): -

      Key Length: 0