Just a thought .

what about a program installed under his user account? I know shouldn't be
like this I had once an updater (hp printer) running under a user account -
caused a lot of trouble and was only seen on that laptop with the local
printer .

Cheers,

Kat 

 

From: [EMAIL PROTECTED]
[mailto:[EMAIL PROTECTED] On Behalf Of Salandra, Justin A.
Sent: Wednesday, 20 December 2006 9:45 AM
To: ActiveDir@mail.activedir.org
Subject: RE: [ActiveDir] Strange Lock Out Issue

 

That is just the thing, no event IDs exist for the account lockout on any DC
even though I have Auditing turned on.  This is why it is a strange lockout.

 

  _____  

From: [EMAIL PROTECTED]
[mailto:[EMAIL PROTECTED] On Behalf Of Brian Desmond
Sent: Monday, December 18, 2006 3:39 PM
To: ActiveDir@mail.activedir.org
Subject: RE: [ActiveDir] Strange Lock Out Issue

 

Eventcombmt the DCs for whatever the lockout ID is also works. 

 

Thanks,

Brian Desmond

[EMAIL PROTECTED]

 

c - 312.731.3132

 

From: [EMAIL PROTECTED]
[mailto:[EMAIL PROTECTED] On Behalf Of WATSON, BEN
Sent: Monday, December 18, 2006 2:50 PM
To: ActiveDir@mail.activedir.org
Subject: RE: [ActiveDir] Strange Lock Out Issue

 

Download the Account Lockout and Management Tools from Microsoft.  More
specifically, from the downloaded EXE, extract the LockoutStatus.EXE file
and use it to query for the user account that is having issues.

 

It will tell you how many bad password attempts have been made, what
time/date the lockout occurred, and on what DC.  Furthermore, you can
directly manage the Domain Controller from the tool and pull up the event
viewer to look for the security entry pointing you to the source of the bad
credentials.

 

It's always worked like a charm for me when dealing with issues like these.

 

Good luck,

~Ben

 

From: [EMAIL PROTECTED]
[mailto:[EMAIL PROTECTED] On Behalf Of Salandra, Justin A.
Sent: Monday, December 18, 2006 11:35 AM
To: ActiveDir@mail.activedir.org
Subject: [ActiveDir] Strange Lock Out Issue

 

I have a user, who is not logged in anywhere else, and while surfing the web
or access a program is getting locked out of her account for no reason.  I
have checked the logs on all three domain controllers and nothing is showing
a failed logon attempt or bad password.  It doesn't even show when the
account got locked.  Any ideas on how to rectify this?

 

Justin A. Salandra

MCSE Windows 2000 & 2003

Network and Technology Services Manager

Catholic Healthcare System

646.505.3681 - office

917.455.0110 - cell

 <mailto:[EMAIL PROTECTED]> [EMAIL PROTECTED]

 

Reply via email to