Solved

AD User accounts appear as locked out in ADUC

Posted on 2006-11-21
3
1,789 Views
Last Modified: 2009-01-07
This is a new one on me and everyone I know:  All my Windows Server 2003 R2 Active Directory user accounts appear locked out in ADUC but aren't, and the object properties show the option to unlock the accounts on the Account tab as disabled.  No other properties on any other tabs seem to be affected.  This is true even when logged in as the root admin account.  Domain structure is pretty flat, one forest, one domain in the forest.  Using a command line utility, I can unlock accounts that are actually locked out, and can enumerate all the user accounts without issue.  Domain level GPO has account lock-out for 30 minutes after 3 tries, with count reset after 29 minutes.  All FSMO roles held by 2003 server, with 3 Win 2K AD servers essentially acting as backups (migrating to 2003 across the board).  The 2003 AD server has been in producton since August without issue.  The Win 2k AD servers have been in production for anywhere from 2 to 5 years.  No obvious errors in any of the event logs on any of the DCs.  Please help!
0
Comment
Question by:slappytheslug
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 2
3 Comments
 
LVL 1

Accepted Solution

by:
ucstechinfo earned 250 total points
ID: 17993960
How do your accounts appear locked-out?

Did you recently change set the lockout setting in a GPO?  I did and freaked for a second as well.  A good test...use a test account and pass enough bad passwords to lock it out.  Then go into the accounts tab and let us know what you see there.  
0
 

Author Comment

by:slappytheslug
ID: 17995226
I changed the account lockout duration to 0 minutes after discovering this issue was domain-wide, and prior to discovering a command line work-around.  Currently, the checkbox on the Account tab in the user object properties that you'd normally uncheck to unlock a user account has "Account is locked out" next to it, and the whole line (including the checkbox) is greyed-out.  I will change the GPO Account lockout duration value back to its original setting and test lockout with a test user account per your recommendation.  I'll report my findings later today - thanks!
0
 

Author Comment

by:slappytheslug
ID: 17996164
I deliberately locked out a test account as recommended and it showed up normally in the ADUC GUI.  I was able to unlock it from there as well.  Perhaps my initial issue was exacerbated by my changing the lockout duration in the root GPO.  Thanks for suggesting this test.  Should have thought of it myself...
0

Featured Post

Office 365 Training for Admins - 7 Day Trial

Learn how to provision tenants, synchronize on-premise Active Directory, implement Single Sign-On, customize Office deployment, and protect your organization with eDiscovery and DLP policies.  Only from Platform Scholar.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Uncontrolled local administrators groups within any organization pose a huge security risk. Because these groups are locally managed it becomes difficult to audit and maintain them.
Group policies can be applied selectively to specific devices with the help of groups. Utilising this, it is possible to phase-in group policies, over a period of time, by randomly adding non-members user or computers at a set interval, to a group f…
This Micro Tutorial hows how you can integrate  Mac OSX to a Windows Active Directory Domain. Apple has made it easy to allow users to bind their macs to a windows domain with relative ease. The following video show how to bind OSX Mavericks to …
Hi friends,  in this video  I'll show you how new windows 10 user can learn the using of windows 10. Thank you.

705 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question