AW: account lockout problems

From: Markgraf, Frank (frank.markgraf@ltg-mailaender.de)
Date: 03/20/02


From: "Markgraf, Frank" <frank.markgraf@ltg-mailaender.de>
To: 'bdoub' <ntbug2000@yahoo.com>, "Markgraf, Frank" <frank.markgraf@ltg-mailaender.de>, "Focus-Ms@Securityfocus. Com" <focus-ms@securityfocus.com>
Date: Wed, 20 Mar 2002 09:35:46 +0100

Is the account really locked or can't the user successfully logon? If the
account isn't locked it seems to be an syncronisation problem with the DCs

Frank

-----Ursprüngliche Nachricht-----
Von: bdoub [mailto:ntbug2000@yahoo.com]
Gesendet: Mittwoch, 20. März 2002 04:53
An: Markgraf, Frank; Focus-Ms@Securityfocus. Com
Cc: barath.br@ajubanet.net
Betreff: RE: account lockout problems

Yes, the "user must logon before password change" is activated. But that
just makes the difference once the account gets locked out. I am much more
interested in finding out why the account gets locked out in the first
place.

Thanks,
Barath

-----Original Message-----
From: Markgraf, Frank [mailto:frank.markgraf@ltg-mailaender.de]
Sent: Tuesday, March 19, 2002 10:23 PM
To: 'bdoub'; Focus-Ms@Securityfocus. Com
Cc: barath.br@ajubanet.net
Subject: AW: account lockout problems

Hi,

Is it possible that you activated the "user must logon bevore pasword
change" key? We have the same problem on some workstations and i think the
cause is the syncronisation between the domain controllers.

mit freundlichen Grüssen

Frank Markgraf
LTG Mailänder GmbH

Tel. +49 711 8201 9156
frank.markgraf@ltg-mailaender.de

Wernerstrasse 119-129
70435 Stuttgart

-----Ursprüngliche Nachricht-----
Von: bdoub [mailto:ntbug2000@yahoo.com]
Gesendet: Dienstag, 19. März 2002 03:27
An: Focus-Ms@Securityfocus. Com
Cc: barath.br@ajubanet.net
Betreff: account lockout problems

Need some help folks,

Server : NT 4.0 sp6a
Clients: win2k prof sp2

Problem Description:
Account policies is setup to change passwords once
in 'X' days with a password history setup.

User gets prompted to change password when
nearing the deadline. User hits 'yes - change
password now' - account gets locked out. Instead if
the user hits 'no - will change password later' and hits ctrl-alt-del and
chooses 'change password' option, the user is able to change the password.

Please Note:
1. I have already looked at articles q263821, q275508,
Q160900 on the MS knowledge base site as mentioned
in the earlier emails on the list, but they all
seem to list problems with a 2k domain, not a NT
domain as is the case with our servers. Most of the other articles on the
technet site also seem to talk more about 2k servers than NT - with respect
to this issue.

2. There are no processes running under the user credentials
at startup.

3. And yes, it happens with all the users and I mean right
from the admins to anyone in the users group. No class distinctions with MS
:)

If there is still some ambiguity, shoot me back an
email at this address.

Thanks,
Barath

_________________________________________________________
Do You Yahoo!?
Get your free @yahoo.com address at http://mail.yahoo.com

_________________________________________________________
Do You Yahoo!?
Get your free @yahoo.com address at http://mail.yahoo.com



Relevant Pages

  • Re: Wierd permissions on user accounts
    ... That said, as I mentioned earlier, your permissions are bad. ... *nobody* will be able to change password on the account. ... I have the following deny rules.. ...
    (microsoft.public.windows.server.active_directory)
  • Re: Wierd permissions on user accounts
    ... If you put in DENY EVERYONE change password, then nobody will ever be able ... > created account and the permissions on that same account after using the ...
    (microsoft.public.windows.server.active_directory)
  • Getting rid of Logon Prompt problem
    ... Go to control panel. ... Click Change Password. ... If this is the only account this should resolve the issue. ... >prompt welcome screen. ...
    (microsoft.public.windowsxp.general)
  • Re: change client password
    ... the properties in the user's account in ADUC does not show that can not ... change password is enabled and that the minimum password age is not set too ... Also make sure that the client computers can contact a domain ... show errors/warnings if a domain controller can not be found or contacted ...
    (microsoft.public.security)
  • User Account setting changed overnight!!!
    ... I have "User can change password" on all users normally ... user connections are not working because they have account ... I can only assume that the User Account ... setting change and account lockout is being caused by ...
    (microsoft.public.windows.server.sbs)