Link to home
Start Free TrialLog in
Avatar of carbonbase
carbonbaseFlag for United Kingdom of Great Britain and Northern Ireland

asked on

account locking out

One of my user accounts keeps getting locked out, at 03 and 33 minutes past the hour a bad password attempt is registered with the domain controller meaning that after 3 bad passwords or every 1.5 hours his account gets locked out.

I have checked user's PC but can't find anything set to run every half hour.  

Here is the event that gets logged on the Domain Controller after each failed logon attempt is generated:



Log Name:      Security
Source:        Microsoft-Windows-Security-Auditing
Date:          11/10/2010 10:03:10 AM
Event ID:      4776
Task Category: Credential Validation
Level:         Information
Keywords:      Audit Failure
User:          N/A
Computer:      MyDomainController.mydomain.com
Description:
The domain controller attempted to validate the credentials for an account.

Authentication Package:      MICROSOFT_AUTHENTICATION_PACKAGE_V1_0
Logon Account:      User that keeps getting locked out
Source Workstation:      My ISA server
Error Code:      0xc000006a
Event Xml:
<Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
  <System>
    <Provider Name="Microsoft-Windows-Security-Auditing" Guid="{54849625-5478-4994-a5ba-3e3b0328c30d}" />
    <EventID>4776</EventID>
    <Version>0</Version>
    <Level>0</Level>
    <Task>14336</Task>
    <Opcode>0</Opcode>
    <Keywords>0x8010000000000000</Keywords>
    <TimeCreated SystemTime="2010-11-10T10:03:10.058Z" />
    <EventRecordID>48935665</EventRecordID>
    <Correlation />
    <Execution ProcessID="604" ThreadID="10492" />
    <Channel>Security</Channel>
    <Computer>MyDomainController.mydomain.com</Computer>
    <Security />
  </System>
  <EventData>
    <Data Name="PackageName">MICROSOFT_AUTHENTICATION_PACKAGE_V1_0</Data>
    <Data Name="TargetUserName">User that keeps getting locked out</Data>
    <Data Name="Workstation">My ISA Server</Data>
    <Data Name="Status">0xc000006a</Data>
  </EventData>
</Event>



The "Source Workstation" is the name of my ISA server, which makes me think maybe it is somthing on the user's PC trying to authenticate with the ISA server.
SOLUTION
Avatar of LHT_ST
LHT_ST

Link to home
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
Start Free Trial
ASKER CERTIFIED SOLUTION
Link to home
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
Start Free Trial
SOLUTION
Link to home
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
Start Free Trial
SOLUTION
Link to home
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
Start Free Trial
SOLUTION
Avatar of johnb6767
johnb6767
Flag of United States of America image

Link to home
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
Start Free Trial
SOLUTION
Link to home
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
Start Free Trial
SOLUTION
Link to home
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
Start Free Trial
Avatar of carbonbase

ASKER

Turns out the problem was the user's active sync mobile phone connection to our exchange server, our active sync traffic passes through our ISA server before it hits our Exchange server.

I have awarded some points as all your answers seemed helpful in troubleshooting account lockout.  Thanks.
Glad youre fixed.....