Today we had several (9) user accounts lock out as if the password lockout policy had been triggered. Although i did not have all logon information being logged so i cannot verify that attempts were not made to log in with incorrect passwords; it happened to some user accounts of users that were not in the office! It happened within a very short period of time(3 minutes) as i immediatly shut down the network when i saw it happening. We have a very secure physical location and a do not allow vpn access(yet). It seemed like some sort of intrusion attempt but some of the obvious accounts (i.e. administrator) were not affected. I should note that AD snap ins like "active directory users and computers" have been very slow lately to open and use(intermittent). All our servers are very new so processing should not be the problem. After checking the usuall suspects, Firewall logs, server logs and physical access and re-enabling user, i brought the network back up and it appears to be fine. Any ideas on what could have cause that to occur?
Start Free Trial