• Status: Solved
  • Priority: Medium
  • Security: Public
  • Views: 1972
  • Last Modified:

Active Directory 2008 Enable Account Lockout Auditing

Hi,

How can I enable the account lockout events in the eventviewer in AD 2008.  Also, what event id's are related to user account lockout?
0
Jack_son_
Asked:
Jack_son_
2 Solutions
 
Mike KlineCommented:
Have a meeting so I can't write more now but look at this  http://www.windowsitpro.com/article/auditing/access-denied-auditing-user-account-lockouts.aspx

I think the event is 644    I'll try and test later to make sure

Thanks

Mike
0
 
modruCommented:
mkline is correct, event ID 644;
http://www.eventid.net/display.asp?eventid=644&eventno=227&source=Security&phase=1

How to enable logging of these events;
To effectively troubleshoot account lockout, enable auditing at the domain level for the following events:
Account Logon Events – Failure
Account Management – Success
Logon Events – Failure

http://technet.microsoft.com/en-us/library/cc776964(WS.10).aspx

To modify the GPO for the settings;
http://technet.microsoft.com/en-us/library/cc775412(WS.10).aspx
0

Featured Post

Independent Software Vendors: We Want Your Opinion

We value your feedback.

Take our survey and automatically be enter to win anyone of the following:
Yeti Cooler, Amazon eGift Card, and Movie eGift Card!

Tackle projects and never again get stuck behind a technical roadblock.
Join Now