Solved

How to check what time the AD account was lock out

Posted on 2010-08-12
4
843 Views
Last Modified: 2012-06-27
Hi,

I know that there is a Microsoft Lockout toolkit but it has to be installed on the DC which is out of bounds. Hence is there a alternative to find out what time the particular AD account was locked out and if possible why?

Thanks
0
Comment
Question by:Decarn
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
4 Comments
 
LVL 24

Expert Comment

by:B H
ID: 33426527
accounts that are locked out are either because of bad passwords real quickly, or the account became disabled (expired, or not allowed to log in during this time of day)

both of these can be found in the event logs (start > run > eventvwr > security)
filter the security log for event id 539 to see when it was locked out

you might find more info about why/from where, if you filter for these event id's:
529, 644, 675, 676, 681, 12294
0
 
LVL 3

Expert Comment

by:jaswinder108
ID: 33426533
Try enable advance features in A.D MMC and then click user properties to see if you get the required details.
0
 
LVL 8

Expert Comment

by:SylvainDrapeau
ID: 33426756
Hello !

You can download this package from Microsoft : http://www.microsoft.com/downloads/details.aspx?FamilyId=7AF2E69C-91F3-4E63-8629-B999ADDE0B9E&displaylang=en

Which contains the utility LockoutStatus.exe and the DLL AcctInfo.dll.

The lockoutstatus utility will give you all the informations you want about, obviously, the lockout status of a user, and the ability to unlock it, reset his password...

Or you can register acctinfo.dll : copy it to C:\Windows\System32 and launch the command "regsvr32 %systemroot%\system32\acctinfo.dll". This will add a tab in the users properties in ADUC that will also give you the information you want.

Syldra
0
 
LVL 2

Accepted Solution

by:
GhouseAdmin earned 500 total points
ID: 33435779
Hi,

You can find detailed information regarding the account status and its usage, when it was locked out, when the user was logged on successfully, how many times user used bad passwords etc.., from:
http://technet.microsoft.com/en-us/library/cc738772%28WS.10%29.aspx

This microsoft site gives more information on different error codes of Account lockout:

http://technet.microsoft.com/en-us/library/cc776964%28WS.10%29.aspx

You can find all the information that you wanted in above mentioned sites.


Ghouse Mohiddin

0

Featured Post

Free Webinar: AWS Backup & DR

Join our upcoming webinar with experts from AWS, CloudBerry Lab, and the Town of Edgartown IT to discuss best practices for simplifying online backup management and cutting costs.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

This is pretty cool.  The purpose of this VB Script is to help you document where JAR (Java ARchive) files and specifically java class files are located so that you can address issues seen with a client or that you can speak intelligently with a dev…
Deploying a Microsoft Access application in a Citrix environment is not difficult but takes a few steps. However, Citrix system people are often of little help, as they typically know next to nothing about Access. The script provided here will take …
Exchange organizations may use the Journaling Agent of the Transport Service to archive messages going through Exchange. However, if the Transport Service is integrated with some email content management application (such as an antispam), the admini…

749 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question