Account Lockout Question/Problem



We have two accounts that randomly get locked out, we have auditing enabled
on our DC so I can see Authentication attempts being made using both
accounts. Our account lockout policy is set to lockout accounts after 7
invalid logon attempts. The problem with diagnosing this is that when I check
the security logs in the DC the “source workstations:” come from various
sources such as \\localhost, \\84.120.100.240 \\FILECAF etc basically it
looks like the logon attempts are spoofing their source address. A couple of
users got spyware two months ago but we removed those systems from the
network. The usual suspects for account lockout problems such as mapped
network drives with invalid passwords and services with incorrect cached
credentials don’t apply here. How can I figure out where exactly these logon
attempts are coming from? Our DS’s are win2003 R2 SP2
.



Relevant Pages

  • Re: User Login
    ... filtering so that only this group gets the deny logon locally privilegs. ... the domain group called Domain Users is a member of the local ... put those user accounts into domain group and apply a GPO to the OU ... "Meinolf Weber" wrote: ...
    (microsoft.public.windows.server.active_directory)
  • Re: RODC ...
    ... Win2003 DCs with RODC the WAN link between the RODC and RWDC goes ... Only then the users are able to logon if the WAN link is down. ... The Password Replication Policy acts as an access control list. ... The Password Replication Policy lists the accounts that are permitted ...
    (microsoft.public.windows.server.active_directory)
  • Re: Account Lockout Policies
    ... Deleting user accounts after 30 days of inactivity allows a windows of opportunity of 30 days for an ex-user to re-use the network. ... If a technical solution is unavoidable due to a lack of management buy-in, there are a few ways that it can be achieved. ... Ascertain from those logs when users last logged in and add 30 days. ... From the users logon script, touch a unique file in a common area. ...
    (microsoft.public.security)
  • Re: Disabling Interactive Logon Against Security Group
    ... A less that fully perfect route to consider would be a logon script ... for those accounts that inquires as to what machine is being logged ... question "disable interactive logon privilages against specific OU/User ... If you set this in a GPO then the list that is to be denied that you ...
    (microsoft.public.security)
  • Re: Server 2003 Local Login
    ... No that's not possible, only domain accounts can be used for logon at DCs, ... the same behavior in Windows 2000 Server. ... >> Microsoft MVP - Directory Services ...
    (microsoft.public.windows.server.active_directory)

Quantcast