Solved

Account Lockout

Posted on 2006-07-12
7
667 Views
Last Modified: 2012-08-13
HI, AD2003

I recently changed the Admin password. and i know notice that badpassword attempts are happerning ever few seconds


I know which server is casuing the lockout due to event manager, but no idea how to find out whats causing it.
no MIS staff use this acocunt. no services are used with it, no scheduled tasks etc

how do you go about tracing the source thats locking the account out?

putthe password back to its old one and it stops logging bad passwords.  I do have trusts setup they dont hold passwod info (or do they?)

backup exec, and Symantec AV are also in use but no links to Admin password (that i know of)
0
Comment
Question by:mhamer
7 Comments
 
LVL 3

Expert Comment

by:valrog
ID: 17090467
It does sound like you've got a service running using the Admin account.  Are you sure that you've checked all of them?  Also, make sure that the admin account isn't logged onto the desktop of the server causing the problem.
0
 
LVL 1

Expert Comment

by:neopro2
ID: 17091163
I guess you used this local admin account to install Symantic AV.
I use Sophos which actually asked during setup which local admin account to use. I should have converted it to a domain account but decided to leave it local.
The service is not running as that user but authenticating in behalf of a computer account for there access to the service.

You can increase event logons from gpedit.msc
computer config/windows settings/local policies/Audit policies:

this may assist in resolving
0
 

Author Comment

by:mhamer
ID: 17091586
Valrog  only two services use domain account neither are the one in question
they log out any one not active after 30 mins,   but yes checked and not logged on

Neopro2.


auditing is already on :-(
no local accounts as such on DC's it would have been intalled under this account, but i would have thought that as long as the user name has a working password that should not matter?

The service is not running as that user but authenticating in behalf of a computer account for there access to the service

dont follow
0
 
LVL 1

Expert Comment

by:neopro2
ID: 17092021
My antivirus Manager runs the service "local System"
But it was configured as a local admin account to allow connections from workstations in the domain.
eg:
the workstation loads the pre msi install with a local user account access. This way the users who are not in the domain but are allowed network access can be managed from this account.

Now if the workstations who have installed this application this way with the username and password defined, and i change that password bad password and it will be locked out. I hope i explained that correctly. But this does not mean Symanitc has that option. just something as a possiblity.
0
 
LVL 23

Accepted Solution

by:
TheCleaner earned 500 total points
ID: 17092918
You can troubleshoot this with the Account Lockout tools from MS:

http://www.microsoft.com/downloads/details.aspx?FamilyID=7AF2E69C-91F3-4E63-8629-B999ADDE0B9E&displaylang=en


Other simple things to check is the Scheduled Tasks, if any, and any backup jobs or other scheduled jobs that may be running.
0

Featured Post

PRTG Network Monitor: Intuitive Network Monitoring

Network Monitoring is essential to ensure that computer systems and network devices are running. Use PRTG to monitor LANs, servers, websites, applications and devices, bandwidth, virtual environments, remote systems, IoT, and many more. PRTG is easy to set up & use.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

I have never ceased to be amazed how many problems you can encounter on a fresh install of a Windows operating system.  This is certainly case in point& Unable to complete ANY MSI installation.  This means Windows Updates are failing and I can't …
On July 14th 2015, Windows Server 2003 will become End of Support, leaving hundreds of thousands of servers around the world that still run this 12 year old operating system vulnerable and potentially out of compliance in many organisations around t…
This is a video describing the growing solar energy use in Utah. This is a topic that greatly interests me and so I decided to produce a video about it.
A company’s greatest vulnerability is their email. CEO fraud, ransomware and spear phishing attacks are the no1 threat to a company’s security. Cybercrime is responsible for the largest loss of money to companies today with losses projected to r…

929 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

9 Experts available now in Live!

Get 1:1 Help Now