• Management Pack:  SCOM 2016
  • MP Version:  1.0
  • Released:  10/19/2018
  • Publisher:  Microsoft

Failed Authentication Attempts Check Monitor

  • ID:  Microsoft.SystemCenter.ManagementServer.Security.FailedAuthenticationCheck
  • Description:  Monitors failed authentication attempts to this management server.
  • Target:  Management Server
  • Enabled:  Yes

Operational States

Name State Description
Repeated Event Raised Warning  
Timer Event Raised Success  

Alert Details

Monitor State Message Priority Severity Auto Resolution
Repeated Event Raised (Warning) Failed Authentication Attempts Check High Warning Yes

Run As Profiles

Name
Default

Monitor Knowledgebase

Summary

One or more attempts by a device, a connector, or an agent to authenticate to this management server failed.

Causes

The authentication failures could be due to one of the following causes:

  • The remote certificate was not trusted

  • A device is pending approval

  • The certificate is not imported correctly

  • The management server and the computer attempting to authenticate are configured to use different authentication settings

Resolutions

View the details for the alert to identify the event that triggered the alert.

For event 20072: View the details for the alert to identify the computer that is using an untrusted certificate. Configure the source computer to use a trusted certificate or configure the server running Operations Manager to trust the certificate authority that issued the certificate. For information about configuring certificates refer to the following:

For event 20002: Open the Administration area in the Operations console and click Pending Management. Select objects listed and click Approve or Reject, as appropriate.

For event 21003: Ensure the root certificate of the Certificate Authority that issued the certificate for the computer identified in the alert details is imported to Trusted Root Certification Authorities . For instructions on importing a Trusted Root certificate, see the topic for your type of certificate authority in Authentication and Data Encryption for Windows Computers (http://go.microsoft.com/fwlink/?LinkId=161162).

For event 21011: Check the authentication settings for both computers in Group Policy and Local Security Policy.

External References
This monitor does not contain any external references.

See Also for SCOM 2016 Management Pack


Downloads for SCOM 2016 Management Pack

AZURE OPTIMIZATION ASSESSMENT GET STARTED
MIGRATION TO AZURE GET STARTED
SYSTEM CENTER MIGRATION TO AZURE GET STARTED
MIGRATION TO AZURE FOR SQL AND WINDOWS 2008 GET STARTED