Finding who disabled account


A user account was disabled today, I want to find out, when, why this was done and who did it. She was logged in today in the morning. Could it be done automatically by Windows?

We're in a SBS2003 environment.

Who is Participating?
Todd GerbertConnect With a Mentor IT ConsultantCommented:
By default I believe only Logons and Logoffs are logged in the Security Log (at least that's the case on my Server 2003 system, I can't speak to SBS).  If Account Management logging was turned off at the time your user's account disabled, then that action would not have been logged.

What might help is look and see who else (especially those users with access to modify an account) logged onto the server at about the same time your users account became disabled.
yes this is possible due to account lockout which will disable the account if the failed logon attempts threshold limit has been reached.
there is no way directly to find out who disabled it if that was the case.
But you can look at the security logs and see who logged in around that time or was already logged on then.
Mike KlineCommented:
You have to have enabled auditing, check the auditing policy for the DCs

Computer Configuration | Windows Settings | Security Settings | Local Policies | Audit Policy

For account access like passwords and accounts being disabled look to see if "Audit Account Management" is set to Success.

If it is or if it is not once you set it then you will look through your security logs for event 629

You will be looking at the security event log on that DC.


Has Powershell sent you back into the Stone Age?

If managing Active Directory using Windows Powershell® is making you feel like you stepped back in time, you are not alone.  For nearly 20 years, AD admins around the world have used one tool for day-to-day AD management: Hyena. Discover why.

run eventvwr.msc and look at the security logs

use the link above with the security log and you will find out who had physical access to the server at tht time.
Here is a sample of event for disabling account.

Caller is the person who disabled it.
event id 629

User Account Changed:
  Account Disabled.
  Target Account Name: Bill
  Target Domain: MS0
  Target Account ID: S-1-5-21-1234561642-8123456618-725345543-1008
  Caller User Name: Administrator
  Caller Domain: ACME
  Caller Logon ID: (0x0,0xD44E)
  Privileges: -
Rommel SultanCommented:
Check the Event viewer.
It should register in Security Log

Sample log
User Account Disabled:
       Target Account Name:      Guest
       Target Domain:      C686724
       Target Account ID:      C686724\Guest
       Caller User Name:      rsultan
       Caller Domain:      COC
       Caller Logon ID:      (0x0,0x1DC49)

For more information, see Help and Support Center at
m2chaudhAuthor Commented:
I want to find out why it was disabled, and who disabled the account in AD. The security audits only show me, this :

Logon Failure:
       Reason:            Account currently disabled
       User Name:      llex
       Domain:            PACSRV
       Logon Type:      3
       Logon Process:      NtLmSsp
       Authentication Package:      NTLM
       Workstation Name:      KAKABEKA07
       Caller User Name:      -
       Caller Domain:      -
       Caller Logon ID:      -
       Caller Process ID:      -
       Transited Services:      -
       Source Network Address:
       Source Port:      1937

If you see the reason field for login failure, it says Account disabled, she didnt have failure logins before this happened. She was logged in this morning. So account was disabled by someone or the Server did it, I want to know what time server or someone disabled her account.
m2chaudhAuthor Commented:
Btw I have enabled her account now, I just want to know, why this happened in the first place. Thanks!
men7sConnect With a Mentor Commented:
the answer will be in the security logs where you were, between this and when she last was logged on, like i said look at the logon types and you will be able to work it out.
Because you are on SBS if you go to server management window then select monitoring i think and scroll to the bottom it should also show you failed logon attempts so then that will rule out account lockout
m2chaudhAuthor Commented:
That was a good idea tgerbert, but it will be hard to say. I've to see, which workstation user was logged on to, and time nd sorting through all the audit entries between this morning and now, is just tedious.

men7s, there has been no failure due to wrong pwd or as such, the account was disabled, thats why it failed logins if at all (thats the reason I see for all failed logins by that person, account disabled). Last time she logged in succesfully was in the morning.

Is there a easier way to find out, or I have to dig through success/fail audits, see who logged on to server during specific time perioid (all day today) etc..
unless you set other auditing options or third party software to monitor, then you are left with these logs to trail through im afraid.
Mike KlineCommented:
You can search through the event logs for specific events, if auditing was on just search/filter for the 629 events


Todd GerbertIT ConsultantCommented:
UNLESS your audit policy was [i]already[/i] set to log such events, I'm afraid your only recourse will be to wade through the logs and hope to see some events that correspond. You probably would have better luck just asking your admins. ;)
Rob WilliamsConnect With a Mentor Commented:
A "Logon Type: 3" tells you this was locked out due to attempted internal access, as opposed to through external access using Remote Web Workplace or Remote desktop.
"Source Network Address:
" tells you from what IP. If this is the IP of the workstation it means either someone at the console tried to logon multiple times unsuccessfully, or a service such as a mapped drive tried to connect.
This is often caused by someone mapping a drive using different credentials and the password expiring.
m2chaudhAuthor Commented:
Thanks for all your help. I think this would require a lot of cross-examination. I was hoping ti wasnt a security breach and as Rob mentioned, it was internal, and we have limited admin access to fewer users in company now.

Thanks for prompt replies!
Question has a verified solution.

Are you are experiencing a similar issue? Get a personalized answer when you ask a related question.

Have a better answer? Share it in a comment.

All Courses

From novice to tech pro — start learning today.