Windows Security Log Event ID 530
Operating Systems Windows Server 2000
Windows XP
Windows Server 2003
CategoryLogon/Logoff
Type Failure
Corresponding events
in Windows 2008
and Vista
4625  
Discussions on Event ID 530
Ask a question about this event

530: Logon Failure - Account logon time restriction violation

On this page

The logon failed because the user attempted to log on outside the account's hour or day of week restrictions. To determine if the user was present at this computer or elsewhere on the network, see the Logon Types chart in event 528.

Event 530 is logged on the workstation or server where the user failed to log on. Event 530 is logged on a domain controller only when a user fails to log on to the domain controller itself (such as at the console or through failure to connect to a shared folder). On workstations and servers, event 530 will be generated only by an attempt to log on with a domain account; local accounts do not offer time restrictions.

To identify the source of network logon failures, check the Workstation Name and Source Network Address fields.

Logon Process and Authentication Package will vary according to the type of logon and authentication protocol used.

  • User Name:
  • Domain:
  • Logon Type:
  • Logon Process:
  • Authentication Package:
  • Workstation Name:

The following fields also appear in Windows Server 2003:

  • Caller User Name:
  • Caller Domain:
  • Caller Logon ID:
  • Caller Process ID:
  • Transited Services:
  • Source Network Address:
  • Source Port:

Top 10 Windows Security Events to Monitor

Logon Failure

Reason: Account logon time restriction violation
User Name: %1
Domain: %2
Logon Type: %3
Logon Process: %4
Authentication Package: %5
Workstation Name: %6

Windows Server 2003 adds these fields:

Caller User Name:-
Caller Domain:-
Caller Logon ID:-
Caller Process ID:-
Transited Services:-
Source Network Address:10.42.42.180
Source Port:0

Keep me up-to-date on the Windows Security Log.
Email*:
*We will NOT share this



Training for the Windows Security Log