Re: Account locking out

From: Steven L Umbach (n9rou_at_nospam-comcast.net)
Date: 06/28/05

  • Next message: Andy Roxburgh: "Admin / Domain Admin rights problem"
    Date: Tue, 28 Jun 2005 09:55:10 -0500
    
    

    I believe if you search the security logs of all the domain controllers for
    lockout events ID's that it may show the user account name and computer
    name - but not 100 percent sure. Just make sure that you have auditing of
    account management enabled in Domain Controller Security Policy also. Event
    Comb will be very useful for you in searching the domain controller security
    logs for specific event ID's. The other thing you could try is to netlogon
    logging on your domain controllers starting with the pdc fsmo. There is a
    free tool to parse the netlogon log looking for logon failures. The link
    below may help which includes tools to use and a link to a white paper on
    account lockouts that also explains netlogon logging. --- Steve

    http://www.microsoft.com/downloads/details.aspx?FamilyId=7AF2E69C-91F3-4E63-8629-B999ADDE0B9E&displaylang=en

    "Molnir" <Molnir@discussions.microsoft.com> wrote in message
    news:4C91D7BA-EF6C-4304-9877-F1810B957758@microsoft.com...
    > I'm on a Windows 2000 domain. We're on a single site with 3 DCs, all
    > configured as GCs. There are approximately 350 users.
    >
    > We have a service account that's suddenly continually locking itself out.
    > I
    > understand that someone somewhere has probably configured something to
    > start
    > using the credentials of this account and probably fat-fingered the
    > password,
    > but I need to determine this down to a machine if possible. We have about
    > 35
    > servers and it will be a huge headache to scour every single machine.
    >
    > The security event log doesn't seem to show me the machine that the
    > lockout
    > is occurring on. The log is set to have a max size of 100 MB and overwrite
    > events as needed; I've exported it to prevent anything relevant from being
    > overwritten. The domain auditing policy is as follows:
    >
    > Account Logon Events S, F
    > Account Management S ,F
    > Directory Service Access S, F
    > Logon Events S, F
    > Object Access S, F
    > Policy Change S, F
    > System Events F
    >
    > Any help would be appreciated.
    >


  • Next message: Andy Roxburgh: "Admin / Domain Admin rights problem"

    Relevant Pages

    • Re: Domain Admins Account.... Locked Out ever 15 minutes
      ... You probably have an account on a machine that has an old password in it. ... Run LockoutStatus.exe from the link below and select the security template. ... > We have two Domain Controllers at headquarter, and two Domain Controllers, ... > Logon Failure: ...
      (microsoft.public.windows.server.active_directory)
    • Re: How can I prevent an account from being locked out?
      ... The security folks pick up on a published ... The lockout threshold is a good ... functionality for the domain ID you need a new domain with that policy. ... password or unlock their account ...
      (microsoft.public.windows.server.active_directory)
    • RE: Account Lockout -- ARGH
      ... I've seen this behaviour with SMS. ... It runs the report with the user account and password supplied to it which, ... > All security events are logged. ... > followed by an account lockout. ...
      (Focus-Microsoft)
    • Re: Windows cannot connect to the domain & Event ID 3210 5722 - Lots of Details!
      ... When a machine joins the domain (Domain Controllers are included in this) it ... back up it is required to log onto the domain, just like a user account. ... from the domain, adding it to a workgroup, then without rebooting ... DNS addresses and there is only one network card in the computer. ...
      (microsoft.public.windows.server.active_directory)
    • Re: Secondary Site on a DC
      ... Completely correct, common idea, just not a good security practice. ... > domain account instead of the computer account? ... > the production environment each of our 28 or so Domain Controllers at remote ... > sites is going to be a Secondary site server. ...
      (microsoft.public.sms.setup)