Want to protect your cyber security and still get fast solutions? Ask a secure question today.Go Premium

x
  • Status: Solved
  • Priority: Medium
  • Security: Public
  • Views: 685
  • Last Modified:

Domain account locks out on computer startup

Hi Experts-

I and one of my coworkers are having an issue where every morning when we come in to work and turn on our laptops, our Windows accounts are locked out. Once unlocked, the accounts stay unlocked until the computer is turned off or restarted. Once the computer comes back up, the accounts lock out again.

Let me say at the get-go that I am not in any way shape or form a domain controller, and have no access to the domain logon servers. We do have a corporate policy where 3 incorrect password attempts will lock out a user account. The web console that performs the unlocking consistently shows 3 bad password attempts from our usernames even though we haven't even logged into Windows yet. Somehow the act of starting Windows sends multiple bad passwords.

I've read as much as I can find online about this problem, and I don't believe it has anything to do with network shares or Windows services, because as I said, the lockouts occur during Windows startup before login. My coworker and I have called our company's help desk and they have exhausted all their resources as well, and the only thing we have to go on are a couple of printouts of the login failure audits (I have attached this document). These do at least show that the lockouts are coming from our own particular laptops, which not only discounts that we're logged in to other computers using old passwords, but also explains why we're both able to log in to other computers without issue.

So without having to access the domain server or look at the Event Log, is there any way to figure out what is causing this problem just for the two of us, while none of the other unit members are experiencing it?
Server-toolbox.doc
0
SeTech
Asked:
SeTech
  • 4
  • 3
1 Solution
 
mjbtecCommented:
It sounds like you're trying to connect to a shared drive that's expecting a different password from what you currently use. Try changing your password from the Ctrl-Alt-Del window.
0
 
SeTechAuthor Commented:
Even before Windows logs in? There are no shared drives connected before Windows even logs in.

Also, neither my coworker nor I began experiencing this problem right after a password change. It began randomly one day with me, about 3 weeks before my next scheduled password change. 2 weeks later, my coworker started having the same problem, and he hadn't changed his password for weeks either.

Like I said, the usual culprits don't seem to match up here.
0
 
Scott1201Commented:
Try removing the network cable from your laptop before you boot your laptop, and leave it unplugged until after you've logged into Windows.  Then re-connect the cable.  (This isn't intended to be a solution, just a troubleshooting step.)  If the account doesn't lock up, then maybe a Windows service is trying to start during system bootup with an incorrect stored password.
0
Automating Your MSP Business

The road to profitability.
Delivering superior services is key to ensuring customer satisfaction and the consequent long-term relationships that enable MSPs to lock in predictable, recurring revenue. What's the best way to deliver superior service? One word: automation.

 
SeTechAuthor Commented:
2 things -
- First off, that's actually what my coworker does to be able to get into the web console that we use to unlock ourselves...my method is just use a spare laptop to access it. So basically, you're spot-on, it doesn't lock us up until our computers are on our company's private network. If we use our laptops from home and log into Windows first, then into the VPN client, we don't get locked out at all.
- Secondly, I had read about Windows Services running under a user name and hadn't really been sure of that, but since you suggest that, I'll be perfectly willing to go along with that idea. So how can I really tell definitively what Windows Services are running at Startup, and under what usernames, so that I can really try and nail this problem down?
0
 
Scott1201Commented:
If you open Control Panel - Administrative Tools - Services you should see a column for "Startup Type" and one for "Log On As".  Anything with "Startup Type" set to Automatic will try to load at system boot.  Check all of the services to see if any are set to log on as a user account.  Most will be Local System, Network Service, or Local Service.

If that doesn't work, you can use Start - Run, msconfig and check the Startup tab.  These are programs that run as you're starting the machine, some will probably be running before you actually log in.  It's feasible to try unchecking a few of these items, then go through the normal steps to see if the lockup happens.  Alternately, if you want to post a list of the startup items, we can try to choose likely culprits to uncheck.
0
 
SeTechAuthor Commented:
Wonderful! This has been plaguing us for almost a year!!!
0
 
SeTechAuthor Commented:
WONDERFUL! Turns out some SQL Server 2005 services were set to Auto and had an old password associated! I disabled them, rebooted, and no lock! Thank you SO MUCH!
0
 
Scott1201Commented:
Setting those services to "manual" and/or correcting the password should fix the problem also, without having to disable the SQL Server functionality.  Glad that worked!
0

Featured Post

Free Tool: SSL Checker

Scans your site and returns information about your SSL implementation and certificate. Helpful for debugging and validating your SSL configuration.

One of a set of tools we are providing to everyone as a way of saying thank you for being a part of the community.

  • 4
  • 3
Tackle projects and never again get stuck behind a technical roadblock.
Join Now