Many domain admin account is locked automaticly in my Active Directory

Posted on 2010-11-30
Last Modified: 2012-05-10

I have many domain controller and RODC in WINDOWS 2008 SP2.

I have many administrator account loocked and i am not able to find the root cause.

When i connect to the server, i and after i enter my password, i have this message:

"the referenced account is currently locked out and may not be logged on to"

Other administrator have the same issue.

After 10-20 minutes, the account is unlocked automaticly.

Thanks for your help
Question by:cawasaki
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 5
  • 4

Author Comment

ID: 34237726

i have used  Account Lockout Status (LockoutStatus.exe) and i see many administrator account with bad password count=3 in the DDC server who host FSMO role.

Any suggestion?
LVL 24

Expert Comment

ID: 34237732
A/c lockout can be with many reason & there can be conficker worms too which mainly target admin accounts.
There can be password guess on the account & you can use netwrix tool to detect.
Industry Leaders: We Want Your Opinion!

We value your feedback.

Take our survey and automatically be enter to win anyone of the following:
Yeti Cooler, Amazon eGift Card, and Movie eGift Card!


Author Comment

ID: 34237751
I have Symmantec SEP 11 in all my server and i have 0 detect!
LVL 24

Expert Comment

ID: 34237766
There can be many reason as i said,mapped drive or service account & its password has been changed, virus attack, if all the domain & admin account facing the issue it can be surely conficker.

Try to cut down the issue,use netwrix tool which helps actually.

Author Comment

ID: 34237778
its possible to find IP of computer try to use administrator account?
LVL 24

Accepted Solution

Awinish earned 500 total points
ID: 34237801
You have to use netwrix or event log from security log to check which computer that admin account is being used.

Use below method to troubleshoot account lockout tool.

Sometime i have seen SEPM is not able to detect Conficker,try to use Mcafee,SOPHOS or trend micro.

Author Comment

ID: 34237865
I have activated a debug log to netlogon, il will report if i see anything

Author Comment

ID: 34238650
ok, i found a computer XP SP3 whot test to connect in all my admin users and lock all my admin account.

I check if it have a virus....

Featured Post

PeopleSoft Has Never Been Easier

PeopleSoft Adoption Made Smooth & Simple!

On-The-Job Training Is made Intuitive & Easy With WalkMe's On-Screen Guidance Tool.  Claim Your Free WalkMe Account Now

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

A project that enables an administrator to perform actions within a user session context not just at the time of login but any time later on day(s) or week(s) later.
A company’s centralized system that manages user data, security, and distributed resources is often a focus of criminal attention. Active Directory (AD) is no exception. In truth, it’s even more likely to be targeted due to the number of companies …
This tutorial will walk an individual through the process of transferring the five major, necessary Active Directory Roles, commonly referred to as the FSMO roles to another domain controller. Log onto the new domain controller with a user account t…
This Micro Tutorial hows how you can integrate  Mac OSX to a Windows Active Directory Domain. Apple has made it easy to allow users to bind their macs to a windows domain with relative ease. The following video show how to bind OSX Mavericks to …

690 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question