Solved

How to check what time the AD account was lock out

Posted on 2010-08-12
4
840 Views
Last Modified: 2012-06-27
Hi,

I know that there is a Microsoft Lockout toolkit but it has to be installed on the DC which is out of bounds. Hence is there a alternative to find out what time the particular AD account was locked out and if possible why?

Thanks
0
Comment
Question by:Decarn
4 Comments
 
LVL 24

Expert Comment

by:B H
ID: 33426527
accounts that are locked out are either because of bad passwords real quickly, or the account became disabled (expired, or not allowed to log in during this time of day)

both of these can be found in the event logs (start > run > eventvwr > security)
filter the security log for event id 539 to see when it was locked out

you might find more info about why/from where, if you filter for these event id's:
529, 644, 675, 676, 681, 12294
0
 
LVL 3

Expert Comment

by:jaswinder108
ID: 33426533
Try enable advance features in A.D MMC and then click user properties to see if you get the required details.
0
 
LVL 8

Expert Comment

by:SylvainDrapeau
ID: 33426756
Hello !

You can download this package from Microsoft : http://www.microsoft.com/downloads/details.aspx?FamilyId=7AF2E69C-91F3-4E63-8629-B999ADDE0B9E&displaylang=en

Which contains the utility LockoutStatus.exe and the DLL AcctInfo.dll.

The lockoutstatus utility will give you all the informations you want about, obviously, the lockout status of a user, and the ability to unlock it, reset his password...

Or you can register acctinfo.dll : copy it to C:\Windows\System32 and launch the command "regsvr32 %systemroot%\system32\acctinfo.dll". This will add a tab in the users properties in ADUC that will also give you the information you want.

Syldra
0
 
LVL 2

Accepted Solution

by:
GhouseAdmin earned 500 total points
ID: 33435779
Hi,

You can find detailed information regarding the account status and its usage, when it was locked out, when the user was logged on successfully, how many times user used bad passwords etc.., from:
http://technet.microsoft.com/en-us/library/cc738772%28WS.10%29.aspx

This microsoft site gives more information on different error codes of Account lockout:

http://technet.microsoft.com/en-us/library/cc776964%28WS.10%29.aspx

You can find all the information that you wanted in above mentioned sites.


Ghouse Mohiddin

0

Featured Post

Efficient way to get backups off site to Azure

This user guide provides instructions on how to deploy and configure both a StoneFly Scale Out NAS Enterprise Cloud Drive virtual machine and Veeam Cloud Connect in the Microsoft Azure Cloud.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Deploying a Microsoft Access application in a Citrix environment is not difficult but takes a few steps. However, Citrix system people are often of little help, as they typically know next to nothing about Access. The script provided here will take …
Restoring deleted objects in Active Directory has been a standard feature in Active Directory for many years, yet some admins may not know what is available.
This video shows how to remove a single email address from the Outlook 2010 Auto Suggestion memory. NOTE: For Outlook 2016 and 2013 perform the exact same steps. Open a new email: Click the New email button in Outlook. Start typing the address: …
This video explains how to create simple products associated to Magento configurable product and offers fast way of their generation with Store Manager for Magento tool.

911 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

23 Experts available now in Live!

Get 1:1 Help Now