User locked out with event 537 under type 11 logon

From: Gijtech (junk_at_gijoes.com)
Date: 11/09/05

  • Next message: lorne: "Permission setup.. help!"
    Date: Wed, 9 Nov 2005 13:56:28 -0800
    
    

    I have a user logging in to the domain from a Win xp sp2 system, who after successfully logging into the domain then logs on to our intranet views an office document then enters the back command and finds his account locked out.

    looking at the event log on the users system reveals one entry of
    Logon Failure: Reason: An error occurred during logon
    User Name: username
    Domain: domain
    Logon Type: 11
    Logon Process: User32
    Authentication Package: Negotiate
    Workstation Name: computer name
    Status code: 0xC000005E
    Substatus code: 0x0

    followed by

    Logon Failure:Reason: Account locked out
    User Name: username
    Domain: domain
    Logon Type: 2
    Logon Process: User32
    Authentication Package: Negotiate
    Workstation Name: computer name

    at this point the user calls and we rest the account. user lockout is set for 5 fails not 1. we have hklm\Software\Microsoft\Windows NT\Current Version\Winlogon\cachedlogonscount set to 0 so I am at a loss as to why the system is attempting to use a cachedinteractive logon, and why is it failing w/ only one attempt.


  • Next message: lorne: "Permission setup.. help!"

    Relevant Pages

    • Re: tracking user log on | log off
      ... Account Logon auditing is enabled in the DDCP ... Terminal Server environment...pretty much everyone uses Terminal Server all day long....Account Logon auditing is enabled via GPO linked to the OU in which the TS Boxes reside... ... Security Logs increased to 256MB on the TS boxes as well. ... This specific client likes this reporting/monitoring stuff....all kinds of requests for this type of stuff. ...
      (microsoft.public.windows.server.active_directory)
    • Re: Hacking attempts?
      ... Windows logs logon type 3 in most cases when you access a computer from elsewhere on the network. ... One of the most common sources of logon events with logon type 3 is connections to shared folders or printers. ... You can use the IIS logs to track down the ip addressthat are attempting unauthorized login. ...
      (microsoft.public.windows.server.sbs)
    • Re: Please Help
      ... In an Active Directory setup I use logon and logoff scripts that log the ... Use the Event logs. ...
      (microsoft.public.windows.server.active_directory)
    • Re: Login Errors Seem to indicate we are being hacked?
      ... wired LAN and I was wondering if the logins were coming through that. ... Switch on SMTP logging and in the logs you will find the IP to block if you ... Logon Failure: ... Caller User Name: SERVER01$ ...
      (microsoft.public.windows.server.sbs)
    • Re: Log file full of security problems!
      ... "Mark Grantom" wrote: ... Associates version of an antivirus program that comes with my DSL ... Primary Logon ID: ... Disable the logging for the time being; Clear the logs or copy them to ...
      (microsoft.public.windowsxp.network_web)

    Loading