Tek-Tips is the largest IT community on the Internet today!

Members share and learn making Tek-Tips Forums the best source of peer-reviewed technical information on the Internet!

  • Congratulations Wanet Telecoms Ltd on being selected by the Tek-Tips community for having the most helpful posts in the forums last week. Way to Go!

Event ID 643 in Windows 2000 Server

Status
Not open for further replies.

novellmel

MIS
May 12, 2002
52
US
This morning, when I was looking through my Event Viewers for our Windows 2000 Servers, I found the following message:

Date: 4/28/03 Source: Security

Time: 3:55:15A Category: Account Management

Type: Success A Event ID: 643

Description: Domain Policy Changed: Password Policy Modified.


To me, it sounds like it's possible that someone got into our system at 3:55 AM this morning and changed a password policy. There are only 2 Network Administrators who are supposed to do that: Myself and a person I supervise. Neither or us were logged in at that time! Does anyone know what this message might mean?
 
At first, I thought that this was not a recurring event. That was because I had sorted the log the wrong way! The user is always "NT AUTHORITY\SYSTEM" and the times are always odd (2:09 AM, 4:12 AM, etc). Based on the user name, this sounds like some sort of system function. At least, I hope that's what it is.
 
Yeah, sounds like a group policy being refreshed. I wouldn't worry about it.

Matt
 
Status
Not open for further replies.

Part and Inventory Search

Sponsor

Back
Top