Account Unlock event not written to the eventlog

From: Aaron Lister (alister@ems-global.com)
Date: 12/23/02


From: "Aaron Lister" <alister@ems-global.com>
Date: Tue, 24 Dec 2002 11:44:13 +1300


Auditing is turned on for:
    Audit Account Logon Events
    Audit Account Management
    Audit Logon Events

Account Lockout Policy is set to the following:
    Account Lockout Duration = 30 mins
    Account Lockout Threshold = 3 invalid attempts
    Reset Account Lockout Counter after = 30 mins

All account lockouts appear in the event log, but only accounts that were
unlocked manually (by an administrator) are logged to the event log.
If the Account lockout duration rule fires to unlock an account, there is no
entry in the event log for this unlock.

Does anyone know why this is so, and how I can capture these unlocks?

Regards
Aaron



Relevant Pages

  • Re: User Locout Issue
    ... troubleshooting account lockout issue is ... the lockout period (Account lockout duration) has expired. ... This security setting determines the number of minutes a locked-out account ... If an account lockout threshold is defined, ...
    (microsoft.public.exchange.admin)
  • Re: Ad2003 - locked-out accounts are not unlocking automatically
    ... What is the scope of the problem exactly? ... What do you see in the event logs of the domain controllers (seems like ... Account lockout threshold: 10 invalid logon attempts ... The only way to unlock that account is user the VBS script with this ...
    (microsoft.public.windows.server.active_directory)
  • Re: multiple account lockouts
    ... If your reset account lockout counter is a> value than the account lockout duration, change it to a lower value and ... The domain security policy is set to ... Once I logged out of the Mac server, ...
    (microsoft.public.windows.server.sbs)
  • Re: Whats the difference
    ... > Account lockout duration and Reset account lockout counter ... "Account lockout duration" means: ... "Reset account lockout counter after" means: ...
    (microsoft.public.win2000.active_directory)
  • Re: Account Policies - NT
    ... Account lockout duration Forever ... guess that your policies are default policies in NT. ...
    (microsoft.public.windows.group_policy)