Remote WMI queries succeed, but DCOM ComplexPing causes Event ID 4625 — how can this be prevented?

Rei Amuro 20 Reputation points
2026-09-25T05:52:54.4+00:00

Microsoft's Open Specifications support team suggested posting this API question under the Win32 API tag.

Question

Our remote WMI queries succeed with explicit credentials, but packet captures show IOXIDResolver::ComplexPing authenticating with the client's local process account instead. The ping is issued by the DCOM/RPCSS runtime on our behalf, not by our code. We are asking about DCOM lifetime-management traffic, including ComplexPing requests with AddToSet and DelFromSet updates.

Is there a supported client-side API to obtain/configure the binding RPCSS uses for ComplexPing, or otherwise make its first authentication attempt use the explicit WMI credentials? If not, is this a documented limitation?

Environment and observations

  • Collector: Windows Server 2022, build 20348.5499, workgroup.
  • Windows service running under a local Administrator account; Java calls a C# DLL using System.Management over DCOM.
  • WMI credentials differ from the service account; collection interval: 180 seconds.

We observed this sequence:

  1. ComplexPing authenticates with the client's local account and receives RPC fault 0x5 (access denied).
  2. A subsequent ComplexPing without RPC authentication succeeds (S_OK).

Collection is unaffected; our problem is only that the first, failed attempt is recorded as Event ID 4625 on the target.

Two failed attempts matched Event ID 4625 on the target domain controller by source address, port, account, and timestamp. The events report Status 0xC000006D and SubStatus 0xC000006A.

In a separate saved test, three ComplexPing requests with DelFromSet=1 also received fault 0x5, followed by successful unauthenticated retries, and matched three 4625 events. The two Server 2022 events above instead involved AddToSet=1 and DelFromSet=0. We therefore do not assume that the failure occurs only during cleanup, or that a particular Dispose call directly triggers a ping.

Connection, enumeration, and cleanup

This simplified excerpt retains the cleanup structure of the baseline DLL path. It is not a standalone reproducer. Inputs come from the caller; event serialization, file output, row-limit/watchdog checks, error handling, and hosting code are omitted.


var options = new ConnectionOptions

{

    Username = username,

    Password = password,

    Authority = "ntlmdomain:" + domain,

    Impersonation = ImpersonationLevel.Impersonate,

    Authentication = AuthenticationLevel.PacketPrivacy,

    EnablePrivileges = true,

    Timeout = TimeSpan.FromSeconds(timeoutSec)

};

var scope = new ManagementScope(

    string.Format(@"\\{0}\ROOT\CIMV2", serverAddress), options);

try

{

    scope.Connect();

    var query = new ObjectQuery(wql);

    var enumerationOptions = new EnumerationOptions

    {

        Rewindable = false,

        ReturnImmediately = true

    };

    using (var searcher = new ManagementObjectSearcher(

        scope, query, enumerationOptions))

    using (var logs = searcher.Get())

    {

        foreach (ManagementObject log in logs.OfType<ManagementObject>())

        {

            using (log)

            {

                // Read and serialize the event here (omitted).

                // Row-limit and watchdog checks are also omitted.

            }

        }

    }

}

finally

{

    scope = null;

}

The using blocks show the cleanup points in our code. We do not equate them with immediate removal of all underlying DCOM references or immediate transmission of a ping. Setting scope to null clears this managed reference; it is not an explicit disconnect. The shortened excerpt has not independently been tested for the 4625 behavior.

Already tried and constraints

In a separate controlled test, CoInitializeSecurity succeeded with the WMI credentials in pAuthList, but the ping identity did not change. Prompt reference release did not consistently prevent the failures in our cleanup tests.

We need to retain the execution account, DLL/DCOM path, prompt reference release, and concurrent collection, without changing settings on monitored systems. Disabling auditing or filtering events does not meet the requirement.

We have read KB 2816192, but have not established whether its explanation applies to this ComplexPing sequence.

Windows development | Windows API - Win32

Answer accepted by question author
Percy Nguyen (WICLOUD CORPORATION) 80 Reputation points Microsoft External Staff Moderator
2026-09-25T08:03:45.5733333+00:00

Hi @Rei Amuro ,

Thank you for the detailed description and packet-level correlation.

Based on the Microsoft public documentation I reviewed, I have not identified a documented client-side API for obtaining or configuring the RPCSS-managed binding used for runtime-generated ComplexPing calls. However, I would not interpret this as confirmation that the behavior is a documented product limitation.

I would like to explain what I found in Microsoft’s documentation.

  • The DCOM specification identifies IObjectExporter as the interface used for OXID resolution, pinging, and server aliveness checks. The Pinging section specifies the RPC binding information and security settings used for SimplePing and ComplexPing, including the credentials of the security principal issuing the request. References: IObjectExporter Methods and Pinging. I read these as protocol requirements, rather than documentation of an application API for accessing RPCSS’s internal binding.
  • Microsoft describes CoSetProxyBlanket as follows: “Sets the authentication information that will be used to make calls on the specified proxy.” Reference: CoSetProxyBlanket. CoInitializeSecurity establishes the default security values for the process. Reference: CoInitializeSecurity. Based on these documented scopes, I would not assume that configuring the WMI proxy or supplying credentials through pAuthList controls the binding used for runtime-generated ComplexPing. I would therefore not present either change as a confirmed solution to your scenario.
  • KB 2816192 states: “The pass-through authentication is always attempted first, even if specific credentials are specified in the tool being used.” Reference: Failed logon event generated when running remote WMI command. However, I do not see a discussion of ComplexPing or the authenticated-failure -> unauthenticated-retry sequence in that article. I would treat it as relevant background, rather than confirmation of the cause of your specific sequence.

I would also suggest a client-side experiment if a separate helper process is acceptable.

One option worth evaluating would be to host the WMI/DCOM collection in a process created using CreateProcessWithLogonW with LOGON_NETCREDENTIALS_ONLY.

Microsoft documents that this flag retains the caller’s local token while creating a new logon session and using the supplied credentials as the process’s default network credentials. Reference: CreateProcessWithLogonW.

I would suggest testing whether ComplexPing issued on behalf of that helper uses those network credentials for its first authentication attempt. I would treat this as an unverified test candidate, not a documented or confirmed workaround, because the API documentation does not guarantee its effect on RPCSS-generated ping traffic.

If you choose to evaluate it, I would recommend an isolated A/B test to verify that:

  • WMI collection still succeeds.
  • ComplexPing is actually captured.
  • The first authentication attempt uses the intended identity and no longer produces the corresponding authentication failure and Event 4625.

I recognize that a helper process would change the hosting arrangement and may fall outside your requirement to retain the existing service/Java/DLL execution path.

If that hosting arrangement must remain unchanged, I would suggest requesting clarification from Microsoft’s Windows COM/RPC support team on whether a supported mechanism exists to control this binding, or whether the observed behavior is an acknowledged limitation. I cannot establish either conclusion from the public documentation reviewed so far.

Hope these information help. If you found my response helpful or informative, I would greatly appreciate it if you could follow this guide for your confirmation.

Thank you.

Was this answer helpful?

1 person found this answer helpful.

0 additional answers

Sort by: Most helpful

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.