Solved

How do I stop users accounts getting locked out?

Posted on 2008-06-26
15
1,893 Views
Last Modified: 2013-12-04
This is a tricky one, since the users are non-domain users, so work LOCALLY from their laptops and not logging into a domain as such. I have ,however, created them accounts in AD in order allow them access to our domain. Basically, they are guests who have their own domain, but obviously cant use or login once they enter our site, but they need to use our printers, access the network resources, etc. I normally get them to do this by Start>Run> type ip address of the domain controller

This then asks them to authenticate their username and password (which I have provided them with). But surprisingly on the first attempt it locks their AD account! I read somewhere its something to do with caching their password somewhere.

Please can someone help, its not affecting everyone, but its really annoying as I cant seem to nail down why its just affecting one user (esp since to my knowledge there are no local policies setup to do this).

thanks
0
Comment
Question by:k3t4n_uk
  • 6
  • 6
15 Comments
 
LVL 6

Expert Comment

by:meugen
ID: 21873542
which is the time difference between clients laptops and the nearest DC?
0
 

Author Comment

by:k3t4n_uk
ID: 21873718
there is no time difference. they are sitting in the same building as the DC.
0
 
LVL 25

Expert Comment

by:slam69
ID: 21873758
My guess would be the password has expired by the time they need to use it again, but as they dont log into the domain they dont get the option to reset it. you could try setting the password to never expire or alternatively increase length of password age
0
 

Author Comment

by:k3t4n_uk
ID: 21874570
I dont want to increase the length of password age in Group policy, as this will prevent users from changing passwords the same day using Outlook Web Access. I had this issue a couple of days ago.

As a result, I havent enforced any Account Lockout policies, and have left them undefined.

Any other ideas?
0
 
LVL 25

Expert Comment

by:slam69
ID: 21874622
you could try stopping credentials being cached but cant see that helping the situation

check teh stored passwords section of users and computers in advanced hit manage passwords...anything showing in their?
0
 

Author Comment

by:k3t4n_uk
ID: 21875622
sorry not sure i follow. are you referring to Active directory?
0
Top 6 Sources for Identifying Threat Actor TTPs

Understanding your enemy is essential. These six sources will help you identify the most popular threat actor tactics, techniques, and procedures (TTPs).

 
LVL 25

Expert Comment

by:slam69
ID: 21877558
sorry no not ad if you go to teh control panel on the machine their is an applet in ther called users and computers have a look in there
0
 

Author Comment

by:k3t4n_uk
ID: 21883886
oh ok. I see. but unfortunately, nothing in there im afraid. One thing I did see however, is that there are various local security lockout and account password policies. Please can someone advise if this is the issue or not.
0
 
LVL 25

Expert Comment

by:slam69
ID: 21883917
you would expect there to be account password policies, however can you be more specific as to what you have being enforced
0
 

Author Comment

by:k3t4n_uk
ID: 21884266
Under Control Panel, Administrative Tools>Local Security Policy

Account Policies
-------------------------
enforce password history=24 passwords remembered
maximum password age=30 days
minimum password age=0 days
min password length=6 chars
password must meet complexity requirements=enabled
store pass usign reversible encryption=disabled

Account lockout policy
----------------------------

Account lockout duration=not applicable
Account lockout threshold=0 invalid logon attempts
Reset account lockout counter after=not applicable



Any ideas???


0
 
LVL 25

Accepted Solution

by:
slam69 earned 500 total points
ID: 21884364
Yup increase the account lockout threshold to 3
0
 

Author Comment

by:k3t4n_uk
ID: 21884394
would this prevent them getting locked out?

they are using start>run

then entering the ip address of the DC. This usually works for them, and prompts for username and password. Lately, its just showing as 'you do not have access to this resource. please see administrator'. Basically words to that effect. If this local policy setting is causing it, shall i change it for all users?
0
 
LVL 25

Expert Comment

by:slam69
ID: 21884430
think its worth a try otherwise they get locke dout straight away Im not 100% this will work but its the next thing to try
0

Featured Post

Better Security Awareness With Threat Intelligence

See how one of the leading financial services organizations uses Recorded Future as part of a holistic threat intelligence program to promote security awareness and proactively and efficiently identify threats.

Join & Write a Comment

In today's information driven age, entrepreneurs have so many great tools and options at their disposal to help turn good ideas into a thriving business. With cloud-based online services, such as Amazon's Web Services (AWS) or Microsoft's Azure, bus…
Our Group Policy work started with Small Business Server in 2000. Microsoft gave us an excellent OU and GPO model in subsequent SBS editions that utilized WMI filters, OU linking, and VBS scripts. These are some of experiences plus our spending a lo…
Excel styles will make formatting consistent and let you apply and change formatting faster. In this tutorial, you'll learn how to use Excel's built-in styles, how to modify styles, and how to create your own. You'll also learn how to use your custo…
You have products, that come in variants and want to set different prices for them? Watch this micro tutorial that describes how to configure prices for Magento super attributes. Assigning simple products to configurable: We assigned simple products…

762 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

19 Experts available now in Live!

Get 1:1 Help Now