Local account ‘CliTest2’ created during Hyper-V failover cluster validation tests

Symptoms:
A temporary local account CliTest2 created on the member of a Hyper-V cluster on behalf of the logged-on administrator when running the flailover cluster validation test wizard or the Test-Cluster Powershell cmdlet, testing the Cluster Shared Volume.
The account is automatically removed once the test finished.

Event ID 4624 is logged in the Security event log when Advanced Audit Policy Configuration is enabled with the process name (CPrepSrv.exe).

Log Name:      Security
Source:        Microsoft-Windows-Security-Auditing
Event ID:      4624
Task Category: Logon
Level:         Information
Keywords:      Audit Success
User:          N/A
Computer:      LONCL01.contoso.com

Description:
An account was successfully logged on.
Subject:
Security ID:                         CONTOSO\admin_joe
Account Name:                admin_joe
Account Domain:                             CONTOSO
Logon ID:                            0x763DEB85

Logon Information:
Logon Type:                       8
Restricted Admin Mode:              –
Virtual Account:                               No
Elevated Token:                               No

Impersonation Level:                    Impersonation

New Logon:
Security ID:                         S-1-5-21-3679121919-4020869419-3007948201-1088
Account Name:                CliTest2
Account Domain:                             LONCL01
Logon ID:                            0x763E7AE9
Linked Logon ID:                              0x0
Network Account Name:             –
Network Account Domain:          –
Logon GUID:                      {00000000-0000-0000-0000-000000000000}

Process Information:
Process ID:                         0xe278
Process Name:                 C:\Windows\System32\CPrepSrv.exe

CliTest2

References:
https://lokna.no/?p=1822