03-28-2017 03:01 PM
Hello, have anyone experienced this? I have patched AD servers over the weekend and ever since then we have lost all the user/ip mappings. I have went over AD settings for the CDA user, all is in order... we have discovered this by accident, because strangely enough WSA works fine (detects identity transparently) even though TUISTATUS shows no mappings....
Solved! Go to Solution.
03-28-2017 11:21 PM
It is a known issue for now. A recent Microsoft security update has caused issues in several customer environments wherein their domain controllers stop logging these 4768 event IDs. The offending KBs are listed below:
KB4012212 (2008) / KB4012213 (2012)
KB4012215 (2008) / KB4012216 (2012)
As a current workaround, users should be able to uninstall the above mentioned KBs and the 4768 event IDs should resume logging. As of the date of this initial publication (3/28/2017), we do not yet know of a permanent fix from Microsoft. There are several threads tracking this issue below:
Reddit:
https://www.reddit.com/r/sysadmin/comments/5zs0nc/
UltimateWindowsSecurity.com:
http://forum.ultimatewindowssecurity.com/Topic7340
Microsoft TechNet:
03-28-2017 11:21 PM
It is a known issue for now. A recent Microsoft security update has caused issues in several customer environments wherein their domain controllers stop logging these 4768 event IDs. The offending KBs are listed below:
KB4012212 (2008) / KB4012213 (2012)
KB4012215 (2008) / KB4012216 (2012)
As a current workaround, users should be able to uninstall the above mentioned KBs and the 4768 event IDs should resume logging. As of the date of this initial publication (3/28/2017), we do not yet know of a permanent fix from Microsoft. There are several threads tracking this issue below:
Reddit:
https://www.reddit.com/r/sysadmin/comments/5zs0nc/
UltimateWindowsSecurity.com:
http://forum.ultimatewindowssecurity.com/Topic7340
Microsoft TechNet:
Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community: