Solved

User Account Automatically locks out in AD on Windows 2003 server

Posted on 2009-07-16
7
590 Views
Last Modified: 2012-05-07
User Account Automatically locks out in AD on Windows 2003 server. This has happened a couple of times. Is there any diagnostics or Fault finding that can be done ?
Can we ascertain whic Pc Is using that user account to log on etc...
Is there any thing that one can do to stop it and to go the bottome of the problem.

thx
adam
0
Comment
Question by:adam_kan2000
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 2
  • 2
  • 2
  • +1
7 Comments
 
LVL 7

Accepted Solution

by:
kumarnirmal earned 125 total points
ID: 24868255
Hi,

This issue might be cause the activity of conflicker worm on your network , you can identified the machines causing account lock from the failure logs on the security logs.

Apply KB958644 & KB890830 and the restart the computer then run "c:\windows\system32\mrt.exe /F:Y to remove conflicker worm.
0
 
LVL 5

Expert Comment

by:ncomper
ID: 24868273
Does this happen when logging into different machines?

Also is the account set to  expire at any point?
0
 
LVL 7

Expert Comment

by:kumarnirmal
ID: 24868321
the account lock out is happening for a particular user or randomly the accounts get locked ?
 
0
Windows Server 2016: All you need to know

Learn about Hyper-V features that increase functionality and usability of Microsoft Windows Server 2016. Also, throughout this eBook, you’ll find some basic PowerShell examples that will help you leverage the scripts in your environments!

 

Author Comment

by:adam_kan2000
ID: 24868801
It is only happening for one user and there is not a lot in the security logs ?
0
 
LVL 4

Assisted Solution

by:DarrenJL
DarrenJL earned 125 total points
ID: 24869649
It does sound a lot like the Conficker worm (http://support.microsoft.com/kb/962007) but it could also be something else.

We use a proxy server to protect our users from the web and occasionally this locks certain users out. One user (Web development) uses Safari as one of their web browsers and that tries multiple times to connect to the web through the proxy server, after the 10th attempt it locks the users account and requires a member of IT to unlock it again.

Our Proxy server is connected via LDAP to our AD infrastructure.

Darren
0
 

Author Comment

by:adam_kan2000
ID: 24877467
Is there any diagnostics work that can be done on the AD

Thx
Adam
0
 
LVL 4

Expert Comment

by:DarrenJL
ID: 24877525
You can enable advanced ldownloading the Account Lockout and Management Tools

http://www.microsoft.com/downloads/details.aspx?FamilyId=7AF2E69C-91F3-4E63-8629-B999ADDE0B9E&displaylang=en

Darren
0

Featured Post

Three Reasons Why Backup is Strategic

Backup is strategic to your business because your data is strategic to your business. Without backup, your business will fail. This white paper explains why it is vital for you to design and immediately execute a backup strategy to protect 100 percent of your data.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

Title # Comments Views Activity
need help with active directory 4 65
Problems with Microsoft.DHCP.PowerShell.Admin Module 4 92
How to rollback Windows updates with SCCM? 6 87
windows Server 2003 in 2017 10 74
Organizations create, modify, and maintain huge amounts of data to help their businesses earn money and generally function.  Typically every network user within an organization has a bit of disk space to store in process items and personal files.   …
A quick step-by-step overview of installing and configuring Carbonite Server Backup.
Although Jacob Bernoulli (1654-1705) has been credited as the creator of "Binomial Distribution Table", Gottfried Leibniz (1646-1716) did his dissertation on the subject in 1666; Leibniz you may recall is the co-inventor of "Calculus" and beat Isaac…
Nobody understands Phishing better than an anti-spam company. That’s why we are providing Phishing Awareness Training to our customers. According to a report by Verizon, only 3% of targeted users report malicious emails to management. With compan…

733 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question