Tx So Much for this explanation
Excessive Security Log Events - Event ID 5379 - Windows 10
I have been experiencing Windows Application crashes on my 3 month old Windows 10 install. While troubleshooting, I noticed that there 50+ security events each minute in the Event Viewer under Windows Logs > Security.
Is this normal?
The majority are Audit Success Messages with the Event ID 5379. There are approximately 50 of these identical messages every minute. Thanks for any insight on this.
See below for typical Message:
Credential Manager credentials were read.
Subject:
Security ID: DESKTOP\*****
Account Name: *****
Account Domain: DESKTOP
Logon ID: 0x354889
Read Operation: Enumerate Credentials
This event occurs when a user performs a read operation on stored credentials in Credential Manager.
Windows for home | Windows 10 | Performance and system failures
Locked Question. This question was migrated from the Microsoft Support Community. You can vote on whether it's helpful, but you can't add comments or replies or follow the question.
52 answers
Sort by: Most helpful
-
Anonymous
2021-05-15T02:02:40+00:00 -
Anonymous
2021-05-13T18:57:16+00:00 1- When you change the buldin accounts passwords like, "default user", "guest" or "administrator"
2- When you disable "server"service. You may get similar warning messages in event viewer, event id 5379, 5382, 4779 that's may little experiences, good luck.tX fOR THIS ANSWER
-
Anonymous
2021-05-13T18:56:06+00:00 Havig some problems last night --- I'm upset because i found any desktop id lay on in my pc
DESKTOP-K90P8Q9 ---- IS THIS DESKTOP OWNER FROM MICROSOFT / GOOGLE OR INTRUDER HACKER OR SOMEONE NEARBY ME
-
Anonymous
2021-05-13T18:40:37+00:00 I have been experiencing Windows Application crashes on my 3 month old Windows 10 install. While troubleshooting, I noticed that there 50+ security events each minute in the Event Viewer under Windows Logs > Security.
Is this normal?
The majority are Audit Success Messages with the Event ID 5379. There are approximately 50 of these identical messages every minute. Thanks for any insight on this.
See below for typical Message:
Credential Manager credentials were read.
Subject:
Security ID: DESKTOP\*****
Account Name: *****
Account Domain: DESKTOP
Logon ID: 0x354889
Read Operation: Enumerate Credentials
This event occurs when a user performs a read operation on stored credentials in Credential Manager.
i had ex[eriences like that last night - my laptop so slowly
-
Anonymous
2021-03-02T12:22:22+00:00 @RemoteComputerTechnician - I would be very interested to know if, after a couple of days use with your suggested workarounds:
1) Have any Event ID 5379 for Audit Success returned?
2) Do all your expected functions (backups, scheduled programs, AV and other Win32 programs) still work OK?
3) Do all of your UWT APPS still work OK?
4) Do all of your sharing/casting and other network activities all still function as normal?
Incidentally, as regards the DefaultAccount (the DSMA account), Microsoft have this to say:
From here:
https://docs.microsoft.com/en-us/windows/security/identity-protection/access-control/local-accounts
Recommendations for managing the Default Account (DSMA)
Microsoft does not recommend changing the default configuration, where the account is disabled. There is no security risk with having the account in the disabled state. Changing the default configuration could hinder future scenarios that rely on this account.