I’ve enabled auditing and noticed a failed attempt to log onto our mail server (the BDC). Nothing unusual, except that this was after hours and it was an attempt to log on as Administrator … The Event Log had our domain name and our mail server name in the details.
My question: does this mean the attempt originated from our domain/this computer, or merely that it was the target? And if it means it was the target, the attempt was from outside, right?