One of the users loses
the ability to login because the security event log is full. When I check
the log, it is filled with event id 534, logon failure, "user has not been
granted the requested logon type at this machine" and it lists a different
user than the one who can't login. The user listed has not made any attempts
to login to this particular machine!
A: Usually, when you see
this type of behavior, you are actually looking at an
application (possibly malware) that is attempting to run a process as the
user indicated in the event log. Your best bet is to track down the
workstation that the problem user is using and inventory any applications
that may be making network calls.