Odd account lockout activity

From: Dr. T. (tony.sinkiewicz_at_rpu.org)
Date: 05/14/03


Date: Wed, 14 May 2003 09:35:53 -0700


Are you running more than one domain? Is there an NT4
and an AD domain with migrated users?

Also check domain policy for expiration times on
passwords and lockouts.

Dr. T.
>-----Original Message-----
>Hi all,
>
>I received several calls today from users complaing that
>their account was locked out.
>
>Our policy is reasonably liberal - 5 logon attempts and
>reset after 20 minutes.
>
>I thought little of it until the third call when I
>started checking the status of all users and discovered
>that every account that I had not already reset was
>locked out.
>
>The only things I could think of that would cause this
is
>either an attempt to compromise the security within the
>timespan I was checking or some odd sort of corruption
in
>the SAM.
>
>I was unable to find any references in the Knowledgebase.
>
>Anyone have any ideas/experiences with this behaviour?
>
>Thanks in advance,
>
>Kevin Whan
>.
>



Relevant Pages

  • RE: Single sign on
    ... How to authentificate an user via telephon? ... > Avatier has a product which would allow users to reset their own passwords ... >> for the person whose account is reset. ... >> would only be accessible by the person whose account is reset. ...
    (Security-Basics)
  • RE: Restrict user
    ... | passwords for user accounts in Active Direcoty. ... | to go about setting up this user to only be able to reset ... Right click on the OU and choose Delegate Control. ... In the delegation of control wizard, select your generic account, then ...
    (microsoft.public.win2000.active_directory)
  • Single sign on
    ... How to authentificate an user via telephon? ... > Avatier has a product which would allow users to reset their own passwords ... >> for the person whose account is reset. ... >> would only be accessible by the person whose account is reset. ...
    (Security-Basics)
  • Re: Login 2000 Problems
    ... passwords to blank, but it says the domain "Patricia" is not available. ... > the same mistake again, and to reset the password for any ... >>> single account they have, and when it fails then they are stuck. ...
    (microsoft.public.win2000.general)
  • Re: RE: How to authentificate an user via telephon?
    ... > Avatier has a product which would allow users to reset their own passwords ... > know where all of the up to 20.000 clients are ... >> for the person whose account is reset. ... >> would only be accessible by the person whose account is reset. ...
    (Security-Basics)