Re: Accounts constantly locking out

From: Vasu (kr_vasudev_at_advantaindia.com)
Date: 11/03/04


Date: Wed, 3 Nov 2004 14:18:40 +0530

Dear William,

Strange things are happening in our domain Controller.

Accounts are automatically getting locked out and clients response time is
very very slow... all these are happening from past 2 days.

We have Win2K with SP4.0 and we have automatic updates set to on.

Could you please let us know how to overcome Automatic Account Lockout
problem.

Thanks in advance

Regards
Vasu

"William Hymen" <t18_pilot@hotmail.spam.com> wrote in message
news:uekEZIUwEHA.2172@TK2MSFTNGP14.phx.gbl...
>I have a two-node Active Directory domain, which I use for change control.
> On these, I have created 400 shares and 200 ID's for dropping-off;
> promoting; and picking-up
> software.
> I create user ID's and permission the ID to the share and the folder.
> The developers drop off the code; and the installers pick it up
> during our green-zone. It has worked well for 5 years... almost!
>
> My users are constantly locking their ID's out; which I then have to
> endlessly connect with telnet and "net user JoeSmith /active:yes "
> to restore the account. No amount of training seems to help,
> and they always seem to map-network-drive and lock themselves out again.
>
> How can I increase the number of failed netbios connections before
> lockouts?,
> or better yet, why does this happen so much?
>
> Thanks in advance-
>
> Bill
>
>



Relevant Pages

  • Re: Security Breach in AD! Help!
    ... > about 5 minutes the user was removed from the built in admin group. ... > changed the default domain policy, the default domain controller policy, ... >> auditing of account logon for success and failure and account management ... >> success and failure in Domain Controller Security Policy. ...
    (microsoft.public.win2000.security)
  • Re: More than one Administrator Account and Reinstalling OS on a D
    ... Some one has created a regular user account and may added that one to ... There is only one built-in administrator peer domain. ... FSMO roles are actually supposed to be transferred automatically during ... When you remove an existing Domain Controller within Active Directory, ...
    (microsoft.public.win2000.active_directory)
  • Re: Security Breach in AD! Help!
    ... I have set up auditing of account logon and account management, ... still allowed to create a user and add the user to the built in admin group ... passwords, but all security updates have been applied. ... > success and failure in Domain Controller Security Policy. ...
    (microsoft.public.win2000.security)
  • Re: More than one Administrator Account and Reinstalling OS on a DC
    ... First to deal with the administrator question, ... administrator account (the one that you can't remove from the administrators ... When you remove an existing Domain Controller within Active Directory, ... Controller you trying to demote is a holder of any of there's. ...
    (microsoft.public.win2000.active_directory)
  • Re: Connecting to DC in wrong site
    ... database does not contain a trust account 'CR02-EMBT30$' referenced by the ... If 'CR02-EMBT30' is not a Domain Controller, it should be disjoined from the ... All the DCs are Global catalogs at the remote sites ...
    (microsoft.public.win2000.active_directory)