Failure Event ID 560 on SC Manager

Failure Event ID 560 on SC Manager

Secure Home | Search | About
 Microsoft Applications Security    Post an article   get this group's latest topics as an RSS feed add this group's latest topics to your My MSN content add this group's latest topics to your My Yahoo content add this group's latest topics to your Google content
Subject Author Date
Failure Event ID 560 on SC Manager ChrisW 10-06-2005
Posted by ChrisW on October 6, 2005, 8:40 am
If you were  Registered and logged in, you could reply and use other advanced thread options
What does this event mean? Thanks, ChrisW.

Event Type: Failure Audit
Event Source: Security
Event Category: Object Access
Event ID: 560

Description:
Object Open:
Object Server: SC Manager
Object Type: SC_MANAGER OBJECT
Object Name: ServicesActive
New Handle ID: -
Operation ID:
Process ID: 388
Primary User Name: MF14$
Primary Domain: MCMCITRIX
Primary Logon ID: (0x0,0x3E7)
Client User Name: jlass
Client Domain: MCMCITRIX
Client Logon ID: (0x0,0x2C7D6FA)
Accesses DELETE
READ_CONTROL
WRITE_DAC
WRITE_OWNER
Connect to service controller
Create a new service
Enumerate services
Lock service database for exclusive access
Query service database lock state
Set last-known-good state of service database

Privileges -


Posted by Steven L Umbach on October 9, 2005, 10:58 am
If you were  Registered and logged in, you could reply and use other advanced thread options
I have seen that if a user tries to run something that requires
administrator privileges and he is not an administrator. For instance if
user jlass had tried to run secpol.msc which is Local Security Policy he
would be denied access if he was not an administrator and that object access
failure event would be recorded [try it and see] though the process ID
would depend on exactly what he was being denied access to. To find the
process ID [other than checking Task Manager - doubtful it will be there]
you could enable auditing of process tracking or it may be recorded in other
object access events. To make it easier to find it use Event Comb [free from
MS] and search the computer security logs for the text string 388 to see if
anything is found. If any events are found they should show the path to the
executable for the process which then may help you in trying to find out
what the users was trying to do. In my case the process was for mmc.exe
indicating that the user tried to access a mmc snapin of which Local
Security Policy is one. I would not worry too much if it is an isolated
event and everything seems to function correctly. --- Steve

http://support.microsoft.com/default.aspx?scid=kb;en-us;308471 -- Event
Comb

> What does this event mean? Thanks, ChrisW.
>
> Event Type: Failure Audit
> Event Source: Security
> Event Category: Object Access
> Event ID: 560
>
> Description:
> Object Open:
> Object Server: SC Manager
> Object Type: SC_MANAGER OBJECT
> Object Name: ServicesActive
> New Handle ID: -
> Operation ID:
> Process ID: 388
> Primary User Name: MF14$
> Primary Domain: MCMCITRIX
> Primary Logon ID: (0x0,0x3E7)
> Client User Name: jlass
> Client Domain: MCMCITRIX
> Client Logon ID: (0x0,0x2C7D6FA)
> Accesses DELETE
> READ_CONTROL
> WRITE_DAC
> WRITE_OWNER
> Connect to service controller
> Create a new service
> Enumerate services
> Lock service database for exclusive access
> Query service database lock state
> Set last-known-good state of service database
>
> Privileges -
>



Similar ThreadsPosted
Failure Event ID 560 on SC Manager October 6, 2005, 8:43 am
Event ID 566 Failure Audit Directory Service Access, unixUserPassw September 26, 2007, 9:44 am
no access to the security log (of the event manager)! September 20, 2006, 10:35 am
Unknown Process/Service: eventm (Event Manager) May 24, 2007, 5:17 am
Failure Audits in Security Log May 18, 2006, 12:00 pm
Security Log Failure Audit November 26, 2006, 12:44 pm
Failure Audit Error 529 December 3, 2007, 11:31 am
Failure Audits 529 & 680: How to track the IP address? July 13, 2005, 3:48 pm
Intermittent Kerberos authentication failure June 14, 2007, 2:26 pm
object access failure audits August 6, 2008, 11:25 am

The site map in XML format XML site map

Contact Us | Privacy Policy