I am getting the following security event log daily at the same time for all local user accounts. They seem to be coming from the machine itself. Any explanation?
Source: Security
Category: Account Management
Type: Failue Audit
Event ID: 627
User: NT AUTHORITY\SYSTEM
COMPUTER: MACHINENAME
Change Password Attempt:
Target Account Name: LOCALUSERACCOUNT
Target Domain: MACHINENAME
Target Account ID: MACHINENAME\LOCALUSERACCOUNT
Caller User Name: MACHINENAME$
Caller Domain: MYDOMAIN
Caller Logon ID: (0x0,0x3E7)
Privileges: -
Source: Security
Category: Account Management
Type: Failue Audit
Event ID: 627
User: NT AUTHORITY\SYSTEM
COMPUTER: MACHINENAME
Change Password Attempt:
Target Account Name: LOCALUSERACCOUNT
Target Domain: MACHINENAME
Target Account ID: MACHINENAME\LOCALUSERACCOUNT
Caller User Name: MACHINENAME$
Caller Domain: MYDOMAIN
Caller Logon ID: (0x0,0x3E7)
Privileges: -