Anonymous Logon being logged when changing passwords

Tony Hodge 96 Reputation points
2020-09-03T09:55:00.783+00:00

So I have a Windows Server 2016 domain and whenever changing a password in Active Directory, even when creating a new account, anonymous logon is being written to the logs (event 4738) even though I'm logged in with a domain administrator account. It does this no matter who makes the password change. I have the following settings applied through group policy and have verified in the registry but it is still occurring:

Network access: Allow anonymous SID/Name translation - Disabled
Network access: Do not allow anonymous enumeration of SAM accounts - Enabled
Network access: Do not allow anonymous enumeration of SAM accounts and shares -Enabled
Network access: Let Everyone permissions apply to anonymous users - Disabled
Network access: Named Pipes that can be accessed anonymously - Enabled and empty
Network access: Shares that can be accessed anonymously - Enabled and empty

For a little bit more information every time I reset a password on the system 3 User Account Management security audit success logs are written. 4767 and 4724 list the correct admin account that made the change. But then 4738 has ANONYMOUS LOGON as the account that made the change. I don't view this as an issue but security is requiring that the anonymous logon not be written ever and it shouldn't be with it disabled in group policy and registry.

Active Directory
Active Directory
A set of directory-based technologies included in Windows Server.
6,149 questions
Windows Server Security
Windows Server Security
Windows Server: A family of Microsoft server operating systems that support enterprise-level management, data storage, applications, and communications.Security: The precautions taken to guard against crime, attack, sabotage, espionage, or another threat.
1,774 questions
0 comments No comments
{count} votes

1 answer

Sort by: Most helpful
  1. Hannah Xiong 6,256 Reputation points
    2020-09-04T02:01:09.58+00:00

    Hello,

    Thank you so much for posting here.

    Here are some discussions here. Hope they would be helpful.

    https://social.technet.microsoft.com/Forums/en-US/cbc5ed8f-da73-483b-9295-d51ff9a2a91c/a-user-account-was-changed-by-anonymous-logon?forum=winserverDS

    https://social.technet.microsoft.com/Forums/en-US/5b2a93f7-7101-43c1-ab53-3a51b2e05693/eventid-4738-user-account-was-changed-by-anonymous?forum=winserverDS

    Thank you so much for your time and support.

    Best regards,
    Hannah Xiong

    ============================================

    If the Answer is helpful, please click "Accept Answer" and upvote it.
    Note: Please follow the steps in our documentation to enable e-mail notifications if you want to receive the related email notification for this thread.