Domain account locks out on computer startup

Posted on 2008-10-22
Medium Priority
Last Modified: 2012-06-27
Hi Experts-

I and one of my coworkers are having an issue where every morning when we come in to work and turn on our laptops, our Windows accounts are locked out. Once unlocked, the accounts stay unlocked until the computer is turned off or restarted. Once the computer comes back up, the accounts lock out again.

Let me say at the get-go that I am not in any way shape or form a domain controller, and have no access to the domain logon servers. We do have a corporate policy where 3 incorrect password attempts will lock out a user account. The web console that performs the unlocking consistently shows 3 bad password attempts from our usernames even though we haven't even logged into Windows yet. Somehow the act of starting Windows sends multiple bad passwords.

I've read as much as I can find online about this problem, and I don't believe it has anything to do with network shares or Windows services, because as I said, the lockouts occur during Windows startup before login. My coworker and I have called our company's help desk and they have exhausted all their resources as well, and the only thing we have to go on are a couple of printouts of the login failure audits (I have attached this document). These do at least show that the lockouts are coming from our own particular laptops, which not only discounts that we're logged in to other computers using old passwords, but also explains why we're both able to log in to other computers without issue.

So without having to access the domain server or look at the Event Log, is there any way to figure out what is causing this problem just for the two of us, while none of the other unit members are experiencing it?
Question by:SeTech
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 4
  • 3

Expert Comment

ID: 22779498
It sounds like you're trying to connect to a shared drive that's expecting a different password from what you currently use. Try changing your password from the Ctrl-Alt-Del window.

Author Comment

ID: 22779558
Even before Windows logs in? There are no shared drives connected before Windows even logs in.

Also, neither my coworker nor I began experiencing this problem right after a password change. It began randomly one day with me, about 3 weeks before my next scheduled password change. 2 weeks later, my coworker started having the same problem, and he hadn't changed his password for weeks either.

Like I said, the usual culprits don't seem to match up here.

Expert Comment

ID: 22779622
Try removing the network cable from your laptop before you boot your laptop, and leave it unplugged until after you've logged into Windows.  Then re-connect the cable.  (This isn't intended to be a solution, just a troubleshooting step.)  If the account doesn't lock up, then maybe a Windows service is trying to start during system bootup with an incorrect stored password.
NFR key for Veeam Backup for Microsoft Office 365

Veeam is happy to provide a free NFR license (for 1 year, up to 10 users). This license allows for the non‑production use of Veeam Backup for Microsoft Office 365 in your home lab without any feature limitations.


Author Comment

ID: 22779675
2 things -
- First off, that's actually what my coworker does to be able to get into the web console that we use to unlock ourselves...my method is just use a spare laptop to access it. So basically, you're spot-on, it doesn't lock us up until our computers are on our company's private network. If we use our laptops from home and log into Windows first, then into the VPN client, we don't get locked out at all.
- Secondly, I had read about Windows Services running under a user name and hadn't really been sure of that, but since you suggest that, I'll be perfectly willing to go along with that idea. So how can I really tell definitively what Windows Services are running at Startup, and under what usernames, so that I can really try and nail this problem down?

Accepted Solution

Scott1201 earned 2000 total points
ID: 22779798
If you open Control Panel - Administrative Tools - Services you should see a column for "Startup Type" and one for "Log On As".  Anything with "Startup Type" set to Automatic will try to load at system boot.  Check all of the services to see if any are set to log on as a user account.  Most will be Local System, Network Service, or Local Service.

If that doesn't work, you can use Start - Run, msconfig and check the Startup tab.  These are programs that run as you're starting the machine, some will probably be running before you actually log in.  It's feasible to try unchecking a few of these items, then go through the normal steps to see if the lockup happens.  Alternately, if you want to post a list of the startup items, we can try to choose likely culprits to uncheck.

Author Closing Comment

ID: 31508879
Wonderful! This has been plaguing us for almost a year!!!

Author Comment

ID: 22779891
WONDERFUL! Turns out some SQL Server 2005 services were set to Auto and had an old password associated! I disabled them, rebooted, and no lock! Thank you SO MUCH!

Expert Comment

ID: 22779974
Setting those services to "manual" and/or correcting the password should fix the problem also, without having to disable the SQL Server functionality.  Glad that worked!

Featured Post

Cyber Threats to Small Businesses (Part 1)

This past May, Webroot surveyed more than 600 IT decision-makers at medium-sized companies to see how these small businesses perceived new threats facing their organizations.  Read what Webroot CISO, Gary Hayslip, has to say about the survey in part 1 of this 2-part blog series.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Managing 24/7 IT Operations is a hands-on job and indeed a difficult one. Over the years I have found some simple tips and techniques to increase the efficiency of the overall operations. The core concept has always been on continuous improvement; a…
Quality of Service (QoS) options are nearly endless when it comes to networks today. This article is merely one example of how it can be handled in a hub-n-spoke design using a 3-tier configuration.
Two types of users will appreciate AOMEI Backupper Pro: 1 - Those with PCIe drives (and haven't found cloning software that works on them). 2 - Those who want a fast clone of their boot drive (no re-boots needed) and it can clone your drive wh…
Monitoring a network: why having a policy is the best policy? Michael Kulchisky, MCSE, MCSA, MCP, VTSP, VSP, CCSP outlines the enormous benefits of having a policy-based approach when monitoring medium and large networks. Software utilized in this v…
Suggested Courses

719 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question