As explained above, if the reference count to a token is not zero, the logon session would not be destroyed which means that a log off session would not be generated.

Down-level domain controllers in trusting domains are not be able to set up a netlogon secure channel. One of the consequences of a token leak that you While null sessions can be used to enumerate users, groups, and shares you can mitigate the risk by using a firewall to prevent internet access to null sessions, enforcing strong passwords

When a user log offs interactively, still an Event ID 538 is generated with Logon Type = 3.

Theoretically, an application closes the handle to the token when its finished with it and this reduces the reference count to it. Windows server doesn't allow connection to shared file or printers with clear text authentication. The only situation I'm aware of are logons from within an ASP script using the ADVAPI. Event Id 551 This caused ~2000 security events on one machine, though those were only event id 538 and 540.

Down-level member workstations or servers are not able to set up a netlogon secure channel.

Similarly, when a user log offs, then under normal conditions, this logon session is destroyed and an entry is made into the Windows Security Log with a Logon ID similar to It is fixed for many cases (but not all) in Service Pack 4.

Event Id 576

Access is only allowed if the remote machine allows NULL session access. Event Id 540 Windows 7 Logoff Event Id Down-level member workstations or servers are not able to set up a netlogon secure channel.

Macintosh users are not able to change their passwords at all.

I had to fix this today, where all computers with Enterprise Manager were polling the server every 10 seconds, and causing those same events. So either the "SuspiciousUser", or someone using his account is accessing something on the machines logging those events.

In other words, a logon session can only be destroyed if the reference count to the token that is associated with it is zero.

Proposed Solution In response to Problem 1, Eric Fitzgerald of Microsoft says, "The issue is a class of bug called a "Token Leak". When the system attempts to access a secured network resource based on NULL credentials, this is referred to as a NULL session. Event ID 538

Event ID 538 can be generated under one of the following conditions: Event ID 538 Possibilities Logon Type Network Logoff 3 Net use disconnection 3 Auto-disconnect 3 Interactive Logoff 2 Logon Type 10 – RemoteInteractive When you access a computer through Terminal Services, Remote Desktop or Remote Assistance windows logs the logon attempt with logon type 10 which makes it easy

Are there any tools I can use to track down where the logins are coming from (Windows firewall logging, perhaps)?