Re: Account Being Locked Somewhere



Turned on all the auditing and waited for it to be locked. Saw this:

Event Type: Success Audit
Event Source: Security
Event Category: Account Management
Event ID: 644
Date: 8/22/2006
Time: 4:53:39 PM
User: NT AUTHORITY\SYSTEM
Computer: DOMAINCONTROLLER
Description:
User Account Locked Out:
Target Account Name: USER
Target Account ID: DOMAIN\USER
Caller Machine Name: DATABASESERVER
Caller User Name: DOMAINCONTROLLER$
Caller Domain: DOMAIN
Caller Logon ID: (0x0,0x000)

It seems he had an old Remote Desktop Connection to the database server that
he had logged in with an old password. Rather than logging off, he had just
closed the window which kept the RDC session open. It must be occasionally
trying to connect using the supplied credentials for some reason.

Connected to the database server, ran Terminal Services Manager, and logged
him off.

Will see if that was the only culprit.


.



Relevant Pages

  • Re: the police was dispatched to ... the wrong house
    ... and ptocessing Caller ID. ... of alarm systems from your garage... ... because of a Caller ID - account number mismatch. ... alarm company to notify them of the change. ...
    (alt.security.alarms)
  • Re: Another security question/issue.
    ... The first event is missing the username and logon process appears 'munged'. ... Caller User Name: MYSERVER-SBS$ ... and, no I have not changed the administrator account password, but I ...
    (microsoft.public.windows.server.sbs)
  • Re: SMS_MP_CONTROL_MANAGER Issues
    ... Since installing SMS2003 service pack 2 I have been receiving the error ... Logon Failure: ... Caller User Name: - ... So after some more research it seems like the account SMS_SQL_RX_999 ...
    (microsoft.public.sms.admin)
  • Re: Excessive Security Success audits
    ... Event Category: Account Management ... Caller Domain: ROSEHILLCAPITAL ... Caller Logon ID: ... Target Server Name: localhost ...
    (microsoft.public.windows.server.sbs)
  • Re: question about burglar alarm dispute (San Francisco Bay Area)
    ... caller ID, so what's the alarm company to do? ... The central stations I know of will begin to bill you ... out the ass if your account goes into run away. ...
    (alt.security.alarms)