Solved

A script to unlock the AD account.

Posted on 2011-03-02
11
1,379 Views
Last Modified: 2012-06-27
A script to unlock the AD account.
I would like to have  a windows script that a specific user can click on to unlock his Active Directory account.
This user  works during Odd hours an no administrator  is available to unlock his AD account.
And also wantto know what kind of permissions that this user will have to achieve this.

Thanks
0
Comment
Question by:jskfan
  • 5
  • 3
  • 3
11 Comments
 
LVL 8

Assisted Solution

by:afthab
afthab earned 250 total points
ID: 35024633
HI,

http://www.experts-exchange.com/Software/Server_Software/File_Servers/Active_Directory/Q_24912703.html

The below tool can provide the feature :

ADSelfService Password management
http://www.manageengine.com/products/self-service-password/
Toll Free: +1-888-720-9500
0
 
LVL 8

Assisted Solution

by:afthab
afthab earned 250 total points
ID: 35024637
0
 
LVL 5

Accepted Solution

by:
NotVeryFat earned 250 total points
ID: 35025681
Save the below as a .vbs file:
If WScript.Arguments.Count = 1 Then
	struser= WScript.Arguments(0)
	Set objUser = GetObject("LDAP://" & struser)
	objUser.IsAccountLocked = False
	objUser.SetInfo
end if

Open in new window


Then run it as filename.vbs LDAP string of user to unlock
e.g. unlockuser.vbs "CN=Smith\, John,OU=domain,OU=com"
0
What is SQL Server and how does it work?

The purpose of this paper is to provide you background on SQL Server. It’s your self-study guide for learning fundamentals. It includes both the history of SQL and its technical basics. Concepts and definitions will form the solid foundation of your future DBA expertise.

 
LVL 5

Assisted Solution

by:NotVeryFat
NotVeryFat earned 250 total points
ID: 35025691
Sorry, correction. Above should read

unlockuser.vbs "CN=Smith\, John,OU=Users,dc=domain,dc=com"
0
 

Author Comment

by:jskfan
ID: 35025773
NotVeryFat:
I run your script but it has done anything
0
 

Author Comment

by:jskfan
ID: 35025797
afthab:

I get this message
Error Unlocking Username On Domainname
0
 

Author Comment

by:jskfan
ID: 35025819
I checked the Active Directory policy
and found this:

Account lockout duration 1440 minutes
Account lockout threshold 6 invalid logon attempts
Reset account lockout counter after 15 minutes

what does each line mean?
I also noticed if I mistype my password just one time instead of 6 as it is indicated in the policy, I got my account locked out
0
 
LVL 5

Assisted Solution

by:NotVeryFat
NotVeryFat earned 250 total points
ID: 35028044
I'm not sure a user can unlock their own account, whatever their priviliges. In order to unlock an account, you need to authenticate with an LDAP server. If the account's locked, then the authentication will fail...
0
 
LVL 8

Assisted Solution

by:afthab
afthab earned 250 total points
ID: 35033802
Account lockout duration : Determines the number of minutes a locked out account remains locked out before automatically becoming unlocked. The range is 1 to 99999 minutes. You can specify that the account will be locked out until an administrator explicitly unlocks it by setting the value to 0.

Account Lockout Threshold : Determines the number of failed logon attempts that will cause a user account to be locked out. A locked out account cannot be used until it is reset by an administrator or the account lockout duration has expired. You can set values between 1 and 999 failed logon attempts, or you can specify that the account will never be locked out by setting the value to 0.

Reset account lockout Counter After: Determines the number of minutes that must elapse after a failed logon attempt before the bad logon attempt counter is reset to 0 bad logons. The range is 1 to 99999 minutes.

Can you check with the corresponding events when the account lockout occur ?

0
 

Author Comment

by:jskfan
ID: 35080770
Account lockout duration 1440 minutes

in my case , does that mean after 24hours I will be able to login ...
of course, after entering the right user name and password ????????
0
 

Author Closing Comment

by:jskfan
ID: 35213023
thanks
0

Featured Post

Netscaler Common Configuration How To guides

If you use NetScaler you will want to see these guides. The NetScaler How To Guides show administrators how to get NetScaler up and configured by providing instructions for common scenarios and some not so common ones.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

This article outlines the process to identify and resolve account lockout in an Active Directory environment.
This article describes my battle tested process for setting up delegation. I use this process anywhere that I need to setup delegation. In the article I will show how it applies to Active Directory
This tutorial will walk an individual through the process of transferring the five major, necessary Active Directory Roles, commonly referred to as the FSMO roles to another domain controller. Log onto the new domain controller with a user account t…
This video shows how to use Hyena, from SystemTools Software, to bulk import 100 user accounts from an external text file. View in 1080p for best video quality.

840 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question