Need to get a list of all users whose accounts got locked out in the last 24hrs

Posted on 2013-05-21
Last Modified: 2013-05-25
We use 2003 AD and have multiple DC. Is there a tools that will get me all of the accounts that got locked out in the last 24hrs?

Question by:rdefino
LVL 10

Expert Comment

ID: 39185810
I never seen an out of the box tool for this ; however you can use many log file watchers such as splunk to record lock out events . Splunk is decent and can be used for other types of reports and log file monitoring.
LVL 10

Expert Comment

ID: 39185818
LVL 10

Expert Comment

ID: 39185835
There are queries that you can write to get the list of currently locked out users ; but it it doesn't give you the list for the past 24 hours.
Is Your AD Toolbox Looking More Like a Toybox?

Managing Active Directory can get complicated.  Often, the native tools for managing AD are just not up to the task.  The largest Active Directory installations in the world have relied on one tool to manage their day-to-day administration tasks: Hyena. Start your trial today.

LVL 54

Expert Comment

ID: 39185842
If a powershell script suits you (i.e. powershell being installed on your 2003 server), I will provide one in 10 hours (when back in the office).

Author Comment

ID: 39185887
I found a free one from MS. eventcomb. Part of Lockout tools.

Searches for locked out accounts.
LVL 18

Expert Comment

by:Sarang Tinguria
ID: 39186246
Please check if below helps

Active Directory Reporting

Accepted Solution

Tushar_Darwatkar earned 500 total points
ID: 39186572

You can user the below account lockout tool which can give you detail information like when the account was locked out, the source and the attempts made as well.
LVL 54

Expert Comment

ID: 39186691
If you are interested in a powershell solution instead of eventcomb, take - needs only small modifications, in this form it will genereate mails promptly whenever an account locks.

Expert Comment

ID: 39187993
You can also try AD Auditor  as a freeware to view the report of locked out users in the last 24 hrs

Also you can schedule this report so that the report will automatically send to you each day at the defined time and mail id.

Featured Post

Free Tool: Subnet Calculator

The subnet calculator helps you design networks by taking an IP address and network mask and returning information such as network, broadcast address, and host range.

One of a set of tools we're offering as a way of saying thank you for being a part of the community.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

Title # Comments Views Activity
Active Directory Account getting mysteriously locked 13 61
active directory 6 29
DNS forwarders "unable to resolve" 1 54
Importing ExtensionAttribute into AD user accounts 10 27
This script can help you clean up your user profile database by comparing profiles to Active Directory users in a particular OU, and removing the profiles that don't match.
This article runs through the process of deploying a single EXE application selectively to a group of user.
This tutorial will walk an individual through the steps necessary to join and promote the first Windows Server 2012 domain controller into an Active Directory environment running on Windows Server 2008. Determine the location of the FSMO roles by lo…
This tutorial will walk an individual through the process of transferring the five major, necessary Active Directory Roles, commonly referred to as the FSMO roles to another domain controller. Log onto the new domain controller with a user account t…

679 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question