Troubleshooting Security events in Server 2012

Mike Garczynski 1 Reputation point
2020-08-27T11:24:51.947+00:00

I am seeing alot of activity in the events log associated with the MSOL_xxxxx account especially off hours. Is this normal or should I be looking for a cause? The event logs samples are below.

Security: A Kerberos authentication ticket (TGT) was requested.
Security: A Kerberos service ticket was requested.
Security: A logon was attempted using explicit credentials.
Security: An account was successfully logged on.
Security: An account was logged off.
Security: A Kerberos authentication ticket (TGT) was requested.
Security: A Kerberos service ticket was requested.
Security: A logon was attempted using explicit credentials.
Security: An account was successfully logged on.
Security: An account was logged off.

Security: An account was successfully logged on.
Security: An operation was performed on an object.
Security: An operation was performed on an object.
Security: An operation was performed on an object.
Security: A Kerberos service ticket was requested.
Security: A logon was attempted using explicit credentials.
Security: An account was successfully logged on.
Security: An account was logged off.
Security: Special privileges assigned to new logon.
Security: An account was successfully logged on.
Security: An account was logged off.
Security: Special privileges assigned to new logon.
Security: An account was successfully logged on.

Windows Server Security
Windows Server Security
Windows Server: A family of Microsoft server operating systems that support enterprise-level management, data storage, applications, and communications.Security: The precautions taken to guard against crime, attack, sabotage, espionage, or another threat.
1,774 questions
0 comments No comments
{count} votes

1 answer

Sort by: Most helpful
  1. Hannah Xiong 6,256 Reputation points
    2020-08-28T02:24:12.717+00:00

    Hello,

    Thank you so much for posting here.

    Once we configured these audit policies, there will be event logs recorded such as:

    Security: A Kerberos authentication ticket (TGT) was requested.
    Security: A logon was attempted using explicit credentials.
    Security: An account was successfully logged on.
    Security: An account was logged off.

    20988-2.png
    21005-3.png

    If lots of accounts log on, there will be lots of activities in the event logs. According to our description, all the event logs are associated with certain account. If we have any doubt, we could verity whether this account is real and existed and then contact the account MSOL_xxxxx account to verify whether this account has preformed the actions.

    For any question, please feel free to contact us.

    Best regards,
    Hannah Xiong