Computer Account Keeps Creating Local User Account

Jesse 1 Reputation point
2021-08-06T06:50:14.28+00:00

Hello

I have had a problem for a while in my network. Several computer accounts keep creating local user accounts and deleting them in a matter of minutes. This occurs in several devices in my environment.

Could this be a service?

Windows 10 Network
Windows 10 Network
Windows 10: A Microsoft operating system that runs on personal computers and tablets.Network: A group of devices that communicate either wirelessly or via a physical connection.
2,276 questions
Windows 10 Security
Windows 10 Security
Windows 10: A Microsoft operating system that runs on personal computers and tablets.Security: The precautions taken to guard against crime, attack, sabotage, espionage, or another threat.
2,767 questions
Windows Server Security
Windows Server Security
Windows Server: A family of Microsoft server operating systems that support enterprise-level management, data storage, applications, and communications.Security: The precautions taken to guard against crime, attack, sabotage, espionage, or another threat.
1,732 questions
Microsoft Entra
0 comments No comments
{count} votes

1 answer

Sort by: Most helpful
  1. VipulSparsh-MSFT 16,236 Reputation points Microsoft Employee
    2021-08-09T05:50:00.387+00:00

    @Jesse You can track that activity to find who created the local user account and then check on that particular server/machine to see what kind of processes are running there. they might or might not have the need for that. normally any service account created by any process would not get deleted and should have valid reason for its existence, I would start from this event logs : https://learn.microsoft.com/en-us/windows/security/threat-protection/auditing/event-4720

    121507-image.png

    Where Account Name [Type = UnicodeString]: the name of the account that requested the “create user account” operation.

    -----------------------------------------------------------------------------------------------------

    Please "Accept the answer" if the information helped you. This will help us and others in the community as well.