Event ID - 16403

Event Id16403
SourceSAM
DescriptionThe error "%2" occurred when trying to create the well known account %1.
Event InformationAccording to Microsoft :
Cause :
This event is logged when the error occurred when trying to create the well known account.
Resolution :
Ensure that the account exists and that it has the correct data
The Security Accounts Manager (SAM) was not able to properly upgrade the account that is identified in the Event Viewer event text. The problem may be related to a resource issue during a database read or write operation, or it may be due to a duplicate account name. Determine if the account was created, and configure the account properties as necessary. If the account was not created or if an account name is duplicated, create an account with a unique name for the account that could not be upgraded. Perform the following procedure using the computer that is logging the event to be resolved.
To perform these procedures, you must have membership in Domain Admins or you must have been delegated the appropriate authority.
Search for the account and verify account properties
To search for the account and verify account properties:
  1. Open Active Directory Users and Computers. To open Active Directory Users and Computers, click Start. In Start Search, type dsa.msc, and then press ENTER. If the User Account Control dialog box appears, confirm that the action it displays is what you want, and then click Continue.
  2. In the console tree, right-click the object that represents your domain, and then click Find. The Find Users, Contacts, and Groups dialog box opens.
  3. In Name, type the account name that is specified in the event text, and then click Find Now:
    • If the account appears in Search results, right-click the account, and then click Properties. Review the account properties to be sure that the account you found represents the account that is named in the event text. Specifically, try to determine that there was not an attempt to create two accounts with the same name.
    • If the account is different from the account that was named in the event text, create an account with a unique name for the account that was named in the event text. Set the properties of the new account to match the properties of the account that is named in the event text.
    • If the account does not appear in Search results, create the account with a unique name and the same user account properties as it had previously.
Create an account using Active Directory Users and Computers
To create an account using Active Directory Users and Computers:
  1. Open Active Directory Users and Computers. To open Active Directory Users and Computers, click Start. In Start Search type dsa.msc, and then press ENTER.
  2. In the console tree, expand the hierarchy of objects.
  3. Right-click the container in which you want to create the new account, click New, and then click the account type that you want to create (such as Computer, Contact, Group, and User). Fill out all the required fields (and any of the appropriate optional fields) in the dialog box that appears for the specific type of account that you selected.
    If you select an account type of User or InetOrgPerson, an additional dialog box appears. Click Next to go to the next dialog box, and then fill out the appropriate information.
  4. When you have filled out all the appropriate information and you are ready to create the account, click OK.
Verify :
To perform this procedure, you must have membership in Domain Admins or you must have been delegated the appropriate authority. Perform the following steps using a domain controller in the domain.
To verify that the well-known accounts exist:
  1. Open a command prompt as an administrator. To open a command prompt as an administrator, click Start. In Start Search, type Command Prompt. At the top of the Start menu, right-click Command Prompt, and then click Run as administrator. If the User Account Control dialog box appears, confirm that the action it displays is what you want, and then click Continue.
  2. Type dsquery * -filter "(objectSID=*)" -limit 44 -attr objectsid distinguishedname %gt wellknownaccounts.txt, and press ENTER. The first 44 accounts in the directory are copied to a text file.
  3. Type notepad wellknownaccounts.txt and press ENTER. The file opens in Notepad.
  4. Check the entries in the list against the following table.
Reference LinksEvent ID 16403 from Source SAM

Catch threats immediately

We work side-by-side with you to rapidly detect cyberthreats
and thwart attacks before they cause damage.

See what we caught

Did this information help you to resolve the problem?

Yes: My problem was resolved.
No: The information was not helpful / Partially helpful.