Event ID 4625 is generated every 30 minutes after enabling application support on an agentless protected VM.
Event ID 4625 Audit Failure Microsoft Windows security auditing.
An account failed to log on.
Subject:
Security ID: NULL SID
Account Name: -
Account Domain: -
Logon ID: 0x0
Logon Type: 3
Account For Which Logon Failed:
Security ID: NULL SID
Account Name: RRCore$
Account Domain: domain.com
Disabling application support will make the Event 4625 to stop.
The Account Name and Domain will match the Rapid Recovery Core server name and domain. You can confirm that information in the next registry key HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\CachedMachineNames\NameUserPrincipal