Still celebrating National IT Professionals Day with 3 months of free Premium Membership. Use Code ITDAY17

x
?
Solved

Account locked out due to 5 login attempts, after 1 attempt

Posted on 2013-05-21
11
Medium Priority
?
710 Views
Last Modified: 2013-06-11
I have a user that when they login first thing in the morning, if they mis-type their password once, it locks out their account. Even though the Group Policy indicates it is 5 times threshold, it only takes them 1 bad password attempt before they're locked out.

Is there a hotfix or possible a local GPO that could be overriding the domain policy?

Windows 7 / ADWin Server 2008
0
Comment
Question by:garryshape
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 4
  • 2
  • 2
  • +3
11 Comments
 
LVL 13

Accepted Solution

by:
markusdamenous earned 400 total points
ID: 39185336
Use group policy modelling to see which is the effective policy controlling this setting.

http://technet.microsoft.com/en-us/library/01be191b-eef8-4f0e-b188-c9281d4a4fc5

That shows how to use the console.
0
 
LVL 56

Assisted Solution

by:McKnife
McKnife earned 400 total points
ID: 39185949
Hi.

> Is there a hotfix or possible a local GPO that could be overriding the domain policy?
No, definitely not. The account lockout policy is in effect at the DC and only there. No local policies will influence domain accounts when it comes to lockouts. About hotfixes: bugs happen here and there, they don't even need hotfixes. That said: I never heard a hotfix did introduce that behavior.

You should make sure that in addition to the password policy there is no PSO active that might override the general settings. Do you know how to check for PSOs? [by the way: the GPO modeling will not tell you about PSOs]
0
 

Author Comment

by:garryshape
ID: 39186106
Yeah not sure if the user is telling the truth or not. Some days it happens, others it doesn't.

Thanks for mentioning PSO, I looked into it just now and doesn't appear to be anything in there (I'm looking in ADSI edit) in the Password Settings Container....

Thinking I should great a GPO just for this user and give 30 attempts within 5 hrs to see if it manages to get locked out again.

Event log source indicates that it is the local user's machine so ....
0
Nothing ever in the clear!

This technical paper will help you implement VMware’s VM encryption as well as implement Veeam encryption which together will achieve the nothing ever in the clear goal. If a bad guy steals VMs, backups or traffic they get nothing.

 
LVL 56

Expert Comment

by:McKnife
ID: 39186122
> Thinking I should great a GPO just for this user
You can't. Password policies are for computers, not for users. But can create a PSO just for him.
0
 
LVL 39

Assisted Solution

by:ChiefIT
ChiefIT earned 400 total points
ID: 39186185
Go to

Control Panel\All Control Panel Items\Credential Manager

and eliminate their old cached logon credentials. Reboot, and you should be fine. Also make sure they are not logged on elsewhere, to include through a VPN connection, or remote desktop.
0
 
LVL 18

Assisted Solution

by:Sarang Tinguria
Sarang Tinguria earned 400 total points
ID: 39186259
can you run gpresult /h c:\gpreport.html and see what password policy is effective on client
0
 
LVL 4

Assisted Solution

by:Tushar_Darwatkar
Tushar_Darwatkar earned 400 total points
ID: 39186505
Hello,

You can user the below account lockout tool which can give you detail information like when the account was locked out, the source and the attempts made as well.

http://www.netwrix.com/account_lockout_examiner.html
0
 
LVL 56

Expert Comment

by:McKnife
ID: 39186701
@sarang_tinguria: the password policies effective at the client don't matter, it's a domain account, so the policies effective at the DC matter as the others only effect local accounts.
0
 
LVL 39

Expert Comment

by:ChiefIT
ID: 39189164
@McKnife:

That's correct, so the end user has a remote session open. This is either a VPN, a service running as the user, or a logon attempt with cached logons from the local computer. SINCE the user gets ONE change before lockout, it leads me to believe this is a CACHED OLD account in Credential Manager that could be wiped out. This is why as a domain admin, I set policy to Prevent Managed credentials on anyone's computer within the domain. That's the very reason that policy exists.

Your thoughts?
0
 
LVL 56

Expert Comment

by:McKnife
ID: 39190256
No thoughts yet, waiting for his test to complete :)
0
 

Author Closing Comment

by:garryshape
ID: 39239524
It appears it was user error all along but these techniques and tools have helped me determine the cause (along with end-user admitting it) and should be of great use going forward.

Thanks again
0

Featured Post

Free Tool: Subnet Calculator

The subnet calculator helps you design networks by taking an IP address and network mask and returning information such as network, broadcast address, and host range.

One of a set of tools we're offering as a way of saying thank you for being a part of the community.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

This article provides a convenient collection of links to Microsoft provided Security Patches for operating systems that have reached their End of Life support cycle. Included operating systems covered by this article are Windows XP,  Windows Server…
IF you are either unfamiliar with rootkits, or want to know more about them, read on ....
This Micro Tutorial will give you a introduction in two parts how to utilize Windows Live Movie Maker to its maximum capability. This will be demonstrated using Windows Live Movie Maker on Windows 7 operating system.
This Micro Tutorial will give you a introduction in two parts how to utilize Windows Live Movie Maker to its maximum editing capability. This will be demonstrated using Windows Live Movie Maker on Windows 7 operating system.

670 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question