Restart OS by Event ID 1074

Vu Manh Tai
Occasional Contributor

How do i stop restart OS by Event ID 1074 ( I Don't Want change password user NTDOMAIN\Administrator )


4 Replies

Hi, I'm not 100% sure if I understood you correctly but you are refering to the Event ID 1074 , which is in the SYSTEM Event Log when a shutdown was initiated. 

Something like that : 

Event Type:       Information
Event Source:    USER32
Event Category: None
Event ID:          1074
Date:                11/24/2011
Time:                7:00:00 AM
User:                NTDOMAIN\Administrator
Computer:         EXCHHTCA


The process winlogon.exe has initiated the restart of computer EXCHHTCA on behalf of user NTDOMAIN\Administrator for the following reason: No title for this reason could be found

 Reason Code: 0x840000ff
 Shutdown Type: restart


Well. How do you stop these? 

Fact #1 the user Domain\Administrator was initiating the shutdown. 

and as you may know you cannot stop and admin. 

Fact #2 if this is unintentional then someone who knows the password of the user domain\administrator (actually the domain admin password!) is shuting down your computer.

Fact #3 if you have so many people in that group that you no longer have control over it it's probably a good time to do some housekeeping and shrink it to a minimum. 

Fact #4 Maybe you have a visitor from the outside and now is really a good time to reset the Administrator password. You may want to consider resetting the KerbTGT Account's password as well. (twice actually!). 


If you have time and if this happens so regularly you may want to enable netlogon logging (nltest /dbflag:0x2080ffff ) and well make sure you have security Auditing enabled and then look at logon occurences shortly before the shutdown was triggert. You can at least find the workstation name / Ip-address from which this was triggert. Of course a local logon may also have happend via RDP from someone with the name "Administrator" but still you would get the client from which he or she did initially connect. 

Happy hunting 




Thank You!
So. I do not stop restart OS by Event ID 1074
Correct, the ID 1074 is an informational Event which serves as a hint for you. If you knwo who and why the machine was rebooted or shutdown there's nothing to worry.
Thank You
Related Conversations
How to Prevent Teams from Auto-Launch
chenrylee in Microsoft Teams on
28 Replies
*Updated 9/3* Syncing in Microsoft Edge Preview Channels
Elliot Kirk in Articles on
201 Replies
Early preview of Microsoft Edge group policies
Sean Lyndersay in Discussions on
65 Replies
Tabs and Dark Mode
cjc2112 in Discussions on
2 Replies