RE: account lockout problems

From: Bill Mote (bill.mote@bigfoot.com)
Date: 03/20/02


From: "Bill Mote" <bill.mote@bigfoot.com>
To: "bdoub" <ntbug2000@yahoo.com>, <fh@rcs.urz.tu-dresden.de>
Date: Wed, 20 Mar 2002 13:20:16 -0500

We experience exactly the same problem. Change password warning is
displayed, but if the user elects to change their password the account gets
locked out. Then it's a trip to the server to unlock the account and have
the user type their new password in the console.

bm

-----Original Message-----
From: bdoub [mailto:ntbug2000@yahoo.com]
Sent: Wednesday, March 20, 2002 6:58 AM
To: fh@rcs.urz.tu-dresden.de; bdoub
Cc: Focus-Ms@Securityfocus. Com
Subject: RE: account lockout problems

Oops, my mistake.

This occurs only with the domain accounts. The local accounts do not have
the same problems.

Thanks,
Barath

-----Original Message-----
From: Frank Heyne [mailto:fh@rcs.urz.tu-dresden.de]
Sent: Wednesday, March 20, 2002 1:50 PM
To: bdoub
Subject: RE: account lockout problems

Did you verify this appearance with the event logs (local and DCs)?
Is the policy the same on WS and DC?
Where is the answer regarding local vs domain accounts?

On 20 Mar 2002, at 9:26, bdoub wrote:

> The account policy is set to lock the account after 3 logins. But here, it
> appears to be locked out at the first login itself.
>
> Thanks,
> Barath
>
> -----Original Message-----
> From: Frank Heyne [mailto:fh@rcs.urz.tu-dresden.de]
> Sent: Tuesday, March 19, 2002 10:52 PM
> To: bdoub
> Subject: Re: account lockout problems
>
>
> 4 Questions:
> What does account lockout policy say?
> How many times is a wrong password allowed until the account locks out
> ... in theory?
> ... in practice?
> Is your problem only with domain accounts or with local accounts as
> well?
>
> On 19 Mar 2002, at 7:56, bdoub wrote:
>
> > Need some help folks,
> >
> > Server : NT 4.0 sp6a
> > Clients: win2k prof sp2
> >
> > Problem Description:
> > Account policies is setup to change passwords once
> > in 'X' days with a password history setup.
> >
> > User gets prompted to change password when
> > nearing the deadline. User hits 'yes - change
> > password now' - account gets locked out. Instead if
> > the user hits 'no - will change password later' and hits
> > ctrl-alt-del and chooses 'change password' option,
> > the user is able to change the password.
> >
> > Please Note:
> > 1. I have already looked at articles q263821, q275508,
> > Q160900 on the MS knowledge base site as mentioned
> > in the earlier emails on the list, but they all
> > seem to list problems with a 2k domain, not a NT
> > domain as is the case with our servers. Most of the other
> > articles on the technet site also seem to talk more about
> > 2k servers than NT - with respect to this issue.
> >
> > 2. There are no processes running under the user credentials
> > at startup.
> >
> > 3. And yes, it happens with all the users and I mean right
> > from the admins to anyone in the users group. No class
> > distinctions with MS :)
> >
> > If there is still some ambiguity, shoot me back an
> > email at this address.
> >
> > Thanks,
> > Barath
> >
> >
> > _________________________________________________________
> > Do You Yahoo!?
> > Get your free @yahoo.com address at http://mail.yahoo.com
> >
>
>
>
> Frank Heyne
>
>
> _________________________________________________________
> Do You Yahoo!?
> Get your free @yahoo.com address at http://mail.yahoo.com
>

Frank Heyne

_________________________________________________________
Do You Yahoo!?
Get your free @yahoo.com address at http://mail.yahoo.com



Relevant Pages

  • Re: Wierd permissions on user accounts
    ... That said, as I mentioned earlier, your permissions are bad. ... *nobody* will be able to change password on the account. ... I have the following deny rules.. ...
    (microsoft.public.windows.server.active_directory)
  • Re: Wierd permissions on user accounts
    ... If you put in DENY EVERYONE change password, then nobody will ever be able ... > created account and the permissions on that same account after using the ...
    (microsoft.public.windows.server.active_directory)
  • Getting rid of Logon Prompt problem
    ... Go to control panel. ... Click Change Password. ... If this is the only account this should resolve the issue. ... >prompt welcome screen. ...
    (microsoft.public.windowsxp.general)
  • RE: account lockout problems
    ... This occurs only with the domain accounts. ... > The account policy is set to lock the account after 3 logins. ... > Is your problem only with domain accounts or with local accounts as ... >> Do You Yahoo!? ...
    (Focus-Microsoft)
  • Re: change client password
    ... the properties in the user's account in ADUC does not show that can not ... change password is enabled and that the minimum password age is not set too ... Also make sure that the client computers can contact a domain ... show errors/warnings if a domain controller can not be found or contacted ...
    (microsoft.public.security)

Quantcast