Event ID 676, Account is locked out

From: Phil Margolies (pmarg@bellsouth.net)
Date: 03/08/03


From: "Phil Margolies" <pmarg@bellsouth.net>
Date: Sat, 8 Mar 2003 12:51:03 -0500


On our domain controllers we are getting a huge amount of failure audit
events in the security log. This is causing the administrator account to
show as being locked out. However, I can still log in to the server as
administrator. Any idea why this is happening and how to stop it? TIA

This is from DC2:

Event Type: Failure Audit
Event Source: Security
Event Category: Account Logon
Event ID: 676
Date: 3/8/2003
Time: 12:35:02 PM
User: NT AUTHORITY\SYSTEM
Computer: DC2
Description:
Authentication Ticket Request Failed:
  User Name: Owner
  Supplied Realm Name: OurDomain.COM
  Service Name: krbtgt/OurDomain.COM
  Ticket Options: 0x40810010
  Failure Code: 0x6
  Client Address: 127.0.0.1

This is from DC1:

Event Type: Failure Audit
Event Source: Security
Event Category: Account Logon
Event ID: 675
Date: 3/8/2003
Time: 12:46:34 PM
User: NT AUTHORITY\SYSTEM
Computer: TEN-NFR-DC-01
Description:
Pre-authentication failed:
  User Name: Administrator
  User ID: NFR\administrator
  Service Name: krbtgt/NFR.COM
  Pre-Authentication Type: 0x2
  Failure Code: 0x18
  Client Address: 172.18.161.152

Event Type: Error
Event Source: SAM
Event Category: None
Event ID: 12294
Date: 3/8/2003
Time: 12:43:38 PM
User: OurDomain\administrator
Computer: DC1
Description:
The SAM database was unable to lockout the account of ? due to a resource
error, such as a hard disk write failure (the specific error code is in the
error data) . Accounts are locked after a certain number of bad passwords
are provided so please consider resetting the password of the account
mentioned above.
Data:
0000: a5 02 00 c0 ¥..À



Relevant Pages


Loading