Re: bad logon attempts against the Unlock dialog box don't count

From: Umit AKKUS [MSFT] (umita_at_online.microsoft.com)
Date: 05/27/04


Date: Thu, 27 May 2004 11:26:29 -0700

Are you trying to unlock the machine with a different user than who has
locked the machine? If so, then the behavior is expected. Otherwise I'm
unable to reproduce the problem (on XP in WS03 domain) you're talking about
below. Can you please send precise steps to reproduce the problem?

Thanks

-- 
This posting is provided "AS IS" with no warranties, and confers no rights.
Umit AKKUS [MSFT]
"JuanMedia" <juanmedia@eresmas.com> wrote in message 
news:15F8CB59-CF39-4474-A3E1-CA4EDA5FCA6A@microsoft.com...
> Hi all,
> I have a quite weird question to ask about the lock user lockout account 
> threshold. We have found in the Windows NT, 2K and XP documentation at the 
> Technet; and also at the msdn websites, this note:
> "Note: Bad logon attempts to a workstation against a password-protected 
> screen saver don't increase the lockout threshold. Similarly, if you lock 
> a server or workstation using Ctrl+Alt+Delete, bad logon attempts against 
> the Unlock dialog box don't count."
> ...but, oh surprise!, we have tested this against three diferent domains 
> (including an old WNT), and the behaviour is exactly the oposite, all 
> failed password attempts count as failed logon. In my opinion this is the 
> correct way to do the unlocking of a workstation, because if not, it would 
> be a higly security risk for the users passwords, obiously. The curious 
> thing is that we have found the above note in several places, but we are 
> not capable of reproduce that behaviour. In all of our tests we allways 
> get the user acount locked.
> Do you know if this is a documentation "mistake"?
> If don't, does someone know how to configure the AD or users workstations, 
> to achieve the behaviour the above note says?
>
> The note above is at the Technet here (for XP): 
> http://www.microsoft.com/technet/prodtechnol/windows2000serv/deploy/confeat/08w2kada.mspx
> The msdn note is here: 
> http://msdn.microsoft.com/library/default.asp?url=/library/en-us/gp/507.asp
>
> Thankyou very much. 


Relevant Pages

  • Re: windows 2000 lock workstation auditing
    ... No events are logged when a workstation is locked. ... You see a logon and logoff event at unlock, ... then destroy the resultant, unneeded logon session. ...
    (microsoft.public.win2000.security)
  • Re: Email on user login/unlock
    ... I want to have a script fire off an email when a user logs in to one ... or when they unlock their session. ... Your best bet to detect when someone logs in is to use a domain-wide logon ... or program would be able to detect when the user unlocked the workstation. ...
    (microsoft.public.windows.server.scripting)
  • User cant log on (weird)
    ... One user keeps experiencing the following--he locks his workstation ... and then can't unlock it. ... code 0x18 which indicates logon failed due to wrong username or password. ... But user has correct username in logon box and is typing password correctly. ...
    (microsoft.public.windows.server.active_directory)
  • Unlocking Workstations
    ... running a pure Windows 2000 Server/Workstation environment with active ... workstation locks after 15 minutes of inactivity. ... or an administrator can unlock the workstation. ... networked workstations is a Domain Administrator. ...
    (microsoft.public.win2000.security)
  • Re: Unlocking Workstations
    ... I'm> running a pure Windows 2000 Server/Workstation environment with active ... I have a policy enabled that makes it so that the> workstation locks after 15 minutes of inactivity. ... only the user> or an administrator can unlock the workstation. ... I had thought about> creating an account called "unlock" that users could use to unlock other> workstations, but there is no way I can have a generic domain administrator> account on my system. ...
    (microsoft.public.win2000.security)