Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people, just like you, are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
Solved

AD User accounts appear as locked out in ADUC

Posted on 2006-11-21
3
1,786 Views
Last Modified: 2009-01-07
This is a new one on me and everyone I know:  All my Windows Server 2003 R2 Active Directory user accounts appear locked out in ADUC but aren't, and the object properties show the option to unlock the accounts on the Account tab as disabled.  No other properties on any other tabs seem to be affected.  This is true even when logged in as the root admin account.  Domain structure is pretty flat, one forest, one domain in the forest.  Using a command line utility, I can unlock accounts that are actually locked out, and can enumerate all the user accounts without issue.  Domain level GPO has account lock-out for 30 minutes after 3 tries, with count reset after 29 minutes.  All FSMO roles held by 2003 server, with 3 Win 2K AD servers essentially acting as backups (migrating to 2003 across the board).  The 2003 AD server has been in producton since August without issue.  The Win 2k AD servers have been in production for anywhere from 2 to 5 years.  No obvious errors in any of the event logs on any of the DCs.  Please help!
0
Comment
Question by:slappytheslug
  • 2
3 Comments
 
LVL 1

Accepted Solution

by:
ucstechinfo earned 250 total points
ID: 17993960
How do your accounts appear locked-out?

Did you recently change set the lockout setting in a GPO?  I did and freaked for a second as well.  A good test...use a test account and pass enough bad passwords to lock it out.  Then go into the accounts tab and let us know what you see there.  
0
 

Author Comment

by:slappytheslug
ID: 17995226
I changed the account lockout duration to 0 minutes after discovering this issue was domain-wide, and prior to discovering a command line work-around.  Currently, the checkbox on the Account tab in the user object properties that you'd normally uncheck to unlock a user account has "Account is locked out" next to it, and the whole line (including the checkbox) is greyed-out.  I will change the GPO Account lockout duration value back to its original setting and test lockout with a test user account per your recommendation.  I'll report my findings later today - thanks!
0
 

Author Comment

by:slappytheslug
ID: 17996164
I deliberately locked out a test account as recommended and it showed up normally in the ADUC GUI.  I was able to unlock it from there as well.  Perhaps my initial issue was exacerbated by my changing the lockout duration in the root GPO.  Thanks for suggesting this test.  Should have thought of it myself...
0

Featured Post

Free Tool: ZipGrep

ZipGrep is a utility that can list and search zip (.war, .ear, .jar, etc) archives for text patterns, without the need to extract the archive's contents.

One of a set of tools we're offering as a way to say thank you for being a part of the community.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Find out how to use Active Directory data for email signature management in Microsoft Exchange and Office 365.
This article outlines the process to identify and resolve account lockout in an Active Directory environment.
This is used to tweak the memory usage for your computer, it is used for servers more so than workstations but just be careful editing registry settings as it may cause irreversible results. I hold no responsibility for anything you do to the regist…
This video shows how to use Hyena, from SystemTools Software, to bulk import 100 user accounts from an external text file. View in 1080p for best video quality.

856 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question