Excessive Security Log Events - Event ID 5379 - Windows 10

Anonymous
2020-04-26T06:15:06+00:00

I have been experiencing Windows Application crashes on my 3 month old Windows 10 install. While troubleshooting, I noticed that there 50+ security events each minute in the Event Viewer under Windows Logs > Security.  

Is this normal?  

The majority are Audit Success Messages with the Event ID 5379.  There are approximately 50 of these identical messages every minute. Thanks for any insight on this.

See below for typical Message:

Credential Manager credentials were read.

Subject:

Security ID: DESKTOP\*****

Account Name: *****

Account Domain: DESKTOP

Logon ID: 0x354889

Read Operation: Enumerate Credentials

This event occurs when a user performs a read operation on stored credentials in Credential Manager.

Windows for home | Windows 10 | Performance and system failures

Locked Question. This question was migrated from the Microsoft Support Community. You can vote on whether it's helpful, but you can't add comments or replies or follow the question.

0 comments No comments

52 answers

Sort by: Newest
  1. Anonymous
    2021-05-13T18:57:16+00:00

    1- When you change the buldin accounts passwords like, "default user", "guest" or "administrator"
    2- When you disable "server"service. You may get similar warning messages in event viewer, event id 5379, 5382, 4779 that's may little experiences, good luck.

    tX fOR THIS ANSWER

    Was this answer helpful?

    0 comments No comments
  2. Anonymous
    2021-05-13T18:56:06+00:00

    Havig some problems last night --- I'm upset because i found any desktop id lay on in my pc  

    DESKTOP-K90P8Q9 ---- IS THIS DESKTOP OWNER FROM MICROSOFT / GOOGLE OR INTRUDER HACKER OR SOMEONE NEARBY ME

    Was this answer helpful?

    0 comments No comments
  3. Anonymous
    2021-05-13T18:40:37+00:00

    I have been experiencing Windows Application crashes on my 3 month old Windows 10 install. While troubleshooting, I noticed that there 50+ security events each minute in the Event Viewer under Windows Logs > Security.  

    Is this normal?  

    The majority are Audit Success Messages with the Event ID 5379.  There are approximately 50 of these identical messages every minute. Thanks for any insight on this.

    See below for typical Message:

    Credential Manager credentials were read.

    Subject:

    Security ID: DESKTOP\*****

    Account Name: *****

    Account Domain: DESKTOP

    Logon ID: 0x354889

    Read Operation: Enumerate Credentials

    This event occurs when a user performs a read operation on stored credentials in Credential Manager.

      

    i had ex[eriences like that last night  - my laptop so slowly

    Was this answer helpful?

    0 comments No comments
  4. Anonymous
    2021-03-02T12:22:22+00:00

    @RemoteComputerTechnician - I would be very interested to know if, after a couple of days use with your suggested workarounds:

    1) Have any Event ID 5379 for Audit Success returned?

    2) Do all your expected functions (backups, scheduled programs, AV and other Win32 programs) still work OK?

    3) Do all of your UWT APPS still work OK?

    4) Do all of your sharing/casting and other network activities all still function as normal?

    Incidentally, as regards the DefaultAccount (the DSMA account), Microsoft have this to say:

    From here:

    https://docs.microsoft.com/en-us/windows/security/identity-protection/access-control/local-accounts

    Recommendations for managing the Default Account (DSMA)

    Microsoft does not recommend changing the default configuration, where the account is disabled. There is no security risk with having the account in the disabled state. Changing the default configuration could hinder future scenarios that rely on this account.

    Was this answer helpful?

    0 comments No comments
  5. Anonymous
    2021-03-01T15:52:45+00:00

    OK. I think I have this resolved.

    Go to local users

    Make sure Administrator, DefaultAccount, and WDAGUtilityAccount are all active - not disabled.

    Make sure the Administrator account has a password set.

    Clear the security log and reboot.

    clear the security log again

    reboot

    This fixed my problem.

    Hope it fixes yours too.

    Was this answer helpful?

    0 comments No comments