Solved

Account AD lockout on

Posted on 2013-06-25
13
4,080 Views
Last Modified: 2014-09-10
We have a user who using smart phone using activesync to sync company email. We are running Exchange 2007.

User change the AD password recently and didn't the new password on device. User reported that whenever device sync the email this will cause the password on AD locked.

The Wintel who working on this issue, informed us this AD lockout was due to Exchange CAS server.

They provided the event ID:

A user account was locked out.

Subject:
                Security ID:                          SYSTEM
                Account Name:                   DC09$
                Account Domain:                                Contoso
                Logon ID:                              0x3e7

Account That Was Locked Out:
                Security ID:                          Contoso\sani
                Account Name:                   sani

Additional Information:
                Caller Computer Name:    ExchangeCA02


Please advice if issue AD lock out due to ExchangeCA02
0
Comment
Question by:suriyaehnop
  • 4
  • 4
  • 2
  • +3
13 Comments
 
LVL 63

Expert Comment

by:Simon Butler (Sembee)
ID: 39274111
I don't under what you are actually asking.
If the user changes their password, but doesn't change the password in the phone then it is going to lock out the account. The account lockout will come from Exchange because that is where the authentication is happening. You get a small window where the old password works, but then the user needs to change the password entry on the device.

Simon.
0
 
LVL 5

Expert Comment

by:vin_shooter
ID: 39274256
Hi,

Take back-up and wipe the device(smart phone) (i mean un-install active sync). Then configure active sync in the smart phone. It will work, the lockout issue won't occur again if the source is your smart phone active sync connection.

You can also clear cache in your workstation(may be some cached password stored in workstation can cause this issue). In the Log it is given that through CAS server it's getting locked also better to check for any session exist in CAS server with the user ID.

Thanks..,:)
0
 
LVL 24

Expert Comment

by:Sandeshdubey
ID: 39274404
You need to change password on device too.Change the password in smart phone  and you should be looking good.

There may be many other causes for account locked out.
•user's account in stored user name and passwords
•user's account tied to persistent mapped drive
•user's account as a service account
•user's account used as an IIS application pool identity
•user's account tied to a scheduled task
•un-suspending a virtual machine after a user's pw as changed
•A SMARTPHONE!!!

For more refer KB article:http://technet.microsoft.com/en-us/library/cc773155(WS.10).aspx

Troubleshooting account lockout the Microsoft PSS way:
http://blogs.technet.com/b/instan/archive/2009/09/01/troubleshooting-account-lockout-the-pss-way.aspx
0
 
LVL 9

Expert Comment

by:VirastaR
ID: 39274432
Hi,

Check this

http://www.petri.co.il/forums/showthread.php?t=21486
Exchange 2007 ActiveSync policy locks phones

and

Exchange 2007 CAS AD account lockouts
http://www.networksteve.com/exchange/topic.php/Exchange_2007_CAS_AD_account_lockouts/?TopicId=24814&Posts=0

Hope that helps :)
0
 
LVL 18

Author Comment

by:suriyaehnop
ID: 39276675
Dear All,

I have password policy in AD, whereby any failed attempt more than 3 times, the password will lockout.

Let say password had changed the password due to password age requirement. User is able access laptop/map drive/outlook.

I understand the activesync phone will authenticate with server to sync the email but let say 1st attempt to sync the mail, it should be failed due to password changed.

How frequent the phone will authenticate with server to sync the phone?
0
 
LVL 18

Author Comment

by:suriyaehnop
ID: 39277071
HERE IS FULL LOG:

Log Name:      Security
Source:        Microsoft-Windows-Security-Auditing
Date:          6/26/2013 11:20:03 AM
Event ID:      4625
Task Category: Logon
Level:         Information
Keywords:      Audit Failure
User:          N/A
Computer:      EXCHCA01.site1.CORP.contoso.com
Description:
An account failed to log on.

Subject:
	Security ID:		SYSTEM
	Account Name:		EXCHCA01$
	Account Domain:		site1
	Logon ID:		0x3e7

Logon Type:			8

Account For Which Logon Failed:
	Security ID:		NULL SID
	Account Name:		SANI
	Account Domain:		site1

Failure Information:
	Failure Reason:		Unknown user name or bad password.
	Status:			0xc000006d
	Sub Status:		0xc000006a

Process Information:
	Caller Process ID:	0xc28
	Caller Process Name:	C:\Windows\System32\inetsrv\w3wp.exe

Network Information:
	Workstation Name:	EXCHCA01
	Source Network Address:	200.44.173.196
	Source Port:		28210

Detailed Authentication Information:
	Logon Process:		Advapi  
	Authentication Package:	Negotiate
	Transited Services:	-
	Package Name (NTLM only):	-
	Key Length:		0

This event is generated when a logon request fails. It is generated on the computer where access was attempted.

The Subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe.

The Logon Type field indicates the kind of logon that was requested. The most common types are 2 (interactive) and 3 (network).

The Process Information fields indicate which account and process on the system requested the logon.

The Network Information fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases.

The authentication information fields provide detailed information about this specific logon request.
	- Transited services indicate which intermediate services have participated in this logon request.
	- Package name indicates which sub-protocol was used among the NTLM protocols.
	- Key length indicates the length of the generated session key. This will be 0 if no session key was requested.
Event Xml:
<Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
  <System>
    <Provider Name="Microsoft-Windows-Security-Auditing" Guid="{54849625-5478-4994-a5ba-3e3b0328c30d}" />
    <EventID>4625</EventID>
    <Version>0</Version>
    <Level>0</Level>
    <Task>12544</Task>
    <Opcode>0</Opcode>
    <Keywords>0x8010000000000000</Keywords>
    <TimeCreated SystemTime="2013-06-26T03:20:03.097Z" />
    <EventRecordID>577862646</EventRecordID>
    <Correlation />
    <Execution ProcessID="652" ThreadID="4304" />
    <Channel>Security</Channel>
    <Computer>EXCHCA01.site1.CORP.contoso.com</Computer>
    <Security />
  </System>
  <EventData>
    <Data Name="SubjectUserSid">S-1-5-18</Data>
    <Data Name="SubjectUserName">EXCHCA01$</Data>
    <Data Name="SubjectDomainName">site1</Data>
    <Data Name="SubjectLogonId">0x3e7</Data>
    <Data Name="TargetUserSid">S-1-0-0</Data>
    <Data Name="TargetUserName">SANI</Data>
    <Data Name="TargetDomainName">site1</Data>
    <Data Name="Status">0xc000006d</Data>
    <Data Name="FailureReason">%%2313</Data>
    <Data Name="SubStatus">0xc000006a</Data>
    <Data Name="LogonType">8</Data>
    <Data Name="LogonProcessName">Advapi  </Data>
    <Data Name="AuthenticationPackageName">Negotiate</Data>
    <Data Name="WorkstationName">EXCHCA01</Data>
    <Data Name="TransmittedServices">-</Data>
    <Data Name="LmPackageName">-</Data>
    <Data Name="KeyLength">0</Data>
    <Data Name="ProcessId">0xc28</Data>
    <Data Name="ProcessName">C:\Windows\System32\inetsrv\w3wp.exe</Data>
    <Data Name="IpAddress">200.44.173.196</Data>
    <Data Name="IpPort">28210</Data>
  </EventData>
</Event>

Open in new window


200.44.173.196 is a Load Balancing Hardware for Exchange Client Access
0
Find Ransomware Secrets With All-Source Analysis

Ransomware has become a major concern for organizations; its prevalence has grown due to past successes achieved by threat actors. While each ransomware variant is different, we’ve seen some common tactics and trends used among the authors of the malware.

 
LVL 24

Accepted Solution

by:
Sandeshdubey earned 250 total points
ID: 39277614
If the phone devices is on each time it sync with exchange it will look for authentication.If the invalid attempt passed for x count as mentioned in GPO the account will be locked. The attempts are coming from:200.44.173.196.
0
 
LVL 63

Assisted Solution

by:Simon Butler (Sembee)
Simon Butler (Sembee) earned 250 total points
ID: 39277650
The old password can continue to work for some time after it has been changed, because ActiveSync maintains an extended session.

The behaviour is outlined in this KB article:
http://support.microsoft.com/kb/2612821

Simon.
0
 
LVL 18

Author Comment

by:suriyaehnop
ID: 39313123
The activesync on exchange server was disabled for a week however when we check on u_ex130710.log (today log), it show that there is incoming activesync from SAMSUNG phone. User didn't use this phone anymore(don't know where the phone is :) )

2013-07-10 00:05:03 10.10.10.22 OPTIONS /Microsoft-Server-ActiveSync/default.eas Cmd=OPTIONS&User=Contoso%5Csani&DeviceId=SEC1851C45AFC9B9&DeviceType=SAMSUNGGTN7105 443 Contoso\sani 200.44.173.196 SAMSUNG-GT-N7105/100.40102 401 1 1909 0

How do I can stop this.
0
 
LVL 63

Expert Comment

by:Simon Butler (Sembee)
ID: 39313612
If the user doesn't have the phone, send a wipe command.


Simon.
0
 
LVL 18

Author Comment

by:suriyaehnop
ID: 39313785
Clear-ActiveSyncDevice failed:

[PS] C:\>Clear-ActiveSyncDevice -Identity sani -WhatIf
Clear-ActiveSyncDevice : Cannot bind parameter 'Identity'. Cannot convert value "imtckm" to type "Microsoft.Exchange.Ma
nagement.Tasks.MobileDeviceIdParameter". Error: "sani is not a valid identity string for the mobile device. Call the
Get-ActiveSyncDeviceStatistics cmdlet by providing the -Mailbox property along with the user name. Example: Get-ActiveS
yncDeviceStatistics -Mailbox [user name]
Parameter name: deviceIdentity"
At line:1 char:33
+ Clear-ActiveSyncDevice -Identity  <<<< sani -WhatIf

Shall I enabled the Activesync features on Sani's mailbox? since I disabled it since a week ago
0
 
LVL 63

Expert Comment

by:Simon Butler (Sembee)
ID: 39313969
You will probably need to in order to use ActiveSync commandlets.

Simon.
0
 

Expert Comment

by:G2020
ID: 40314217
I also have a similar problem and spend a lot of tije for finding root cause. You need to check the authentication log to the CAS server (Edge server) under path below if you want to know the root cause.

C:\Program Files\Microsoft\Exchange Server\TransportRoles\Logs\ProtocolLog\SmtpReceive

To solve the problem quickly, what you can try is change the username, ex: peter, change to peter222 at Active Directory.  User also need to update the login ID for his machine and device after you change.

I believe the user won't get "locked out" issue again.

Hope this can help you.
0

Featured Post

How your wiki can always stay up-to-date

Quip doubles as a “living” wiki and a project management tool that evolves with your organization. As you finish projects in Quip, the work remains, easily accessible to all team members, new and old.
- Increase transparency
- Onboard new hires faster
- Access from mobile/offline

Join & Write a Comment

Disabling the Directory Sync Service Account in Office 365 will stop directory synchronization from working.
Local Continuous Replication is a cost effective and quick way of backing up Exchange server data. The following article describes the steps required to configure Local Continuous Replication. Also, the article tells you how to restore from a backup…
In this video we show how to create an Accepted Domain in Exchange 2013. We show this process by using the Exchange Admin Center. Log into Exchange Admin Center.: First we need to log into the Exchange Admin Center. Navigate to the Mail Flow >> Ac…
The basic steps you have just learned will be implemented in this video. The basic steps are shown to configure an Exchange DAG in a live working Exchange Server Environment and manage the same (Exchange Server 2010 Software is used in a Windows Ser…

705 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

14 Experts available now in Live!

Get 1:1 Help Now