Password lockouts in Mixed mode domain

From: Joe (saqib@tsck.org.kw)
Date: 11/18/02


From: "Joe" <saqib@tsck.org.kw>
Date: Sun, 17 Nov 2002 22:43:02 -0800


The Scenario:

* Windows 2000 Server (SP2) - Former NT PDC
* Windows NT 4.0 Server (SP6) - BDC
* Windows 98 Clients
* Account Lockout after 3 bad logons
* Reset Counter after 30 minutes

Some of the users in the network are having constant
problems with their usernames. Before upgrading our NT 4.0
PDC to Windows 2000 DC (Mixed mode) I had no problems, but
after upgrading it 2 weeks ago, I've noticed that some
users passwords get locked out without any logon attempts.
When I check the Event viewer log, I don't find any bad
attempts made by the users, but their account happens to
be locked out, infact one of the users account is getting
locked out every morning for the past 3 days and there is
no mention of bad attempts in the log, whereas, there are
some users who got locked out, but it shows that there
were 3 bad attempts made. I checked the password policy in
my Windows 2000 DC, and it's retained the value of locking
out after 3 bad attempts and hasn't made any changes.
Probably i'm having problems because I'm still in mixed
mode, but then it doesn't make sense, there are companies
out there who can't work in native mode due to some
customised softwares that work only on NT 4.0 and need to
be on a DC. So if anyone out there had a similar problem
or anyone knows the solution, please let me know.

Thanks in advance to whoever solves this problem.



Relevant Pages