Solved

Active directory account keeps getting locked out after I changed my password

Posted on 2014-07-31
5
9,523 Views
Last Modified: 2014-08-13
enterprise domain has 30 day password life. I changed password yesterday. every 30 minutes or so I am getting locked out(windows 7 computer, server2003 domain controller, server 2008r2 member servers).  My password in not used for any service account.  I have checked as many servers as I can but I do not see me being logged in.  Is there any easy way to determine where my account is logged in?  This is driving me crazy.

Thank you,
0
Comment
Question by:BUCKBERG
5 Comments
 
LVL 13

Assisted Solution

by:Gabriel Clifton
Gabriel Clifton earned 125 total points
ID: 40232601
This could be something like a scheduled task or wireless on your phone, anything that might still have your old password stored in it for authentication.
0
 
LVL 3

Assisted Solution

by:Brandon
Brandon earned 125 total points
ID: 40232620
I agree with PantherTech. I had a user change their desktop password yesterday but did not update their iPad at home. Every 30 minutes when the iPad tried to fetch it would cause her account to lock.

I simply removed the device from her email profile and forced her to resync today.
0
 
LVL 77

Assisted Solution

by:Rob Williams
Rob Williams earned 125 total points
ID: 40232655
Another is mapped drives that are saved with credentials and not updated.
0
 
LVL 6

Expert Comment

by:Ricardo Martínez
ID: 40232685
I often have that problem with the users in my domain cause they have their emails configured on their iPhone or Android phone, check for any of those devices, or you can also track with your firewall the traffic from your user (if you have a firewall authenticated with your domain).
0
 
LVL 1

Accepted Solution

by:
Daniel Blackmore earned 125 total points
ID: 40233780
You will be able to see the events in the Event Viewer why your account is being locked out. I believe it is Event ID 644. Make sure that your Security Audit is set to Success/Failure though to see these errors inside the DC's event log.

You will see something like Caller Computer Name or similar which is the device that is causing your account to lock.

Additional, Event ID 529 which is a failed logon attempt should list everywhere that has the wrong credentials saved.
0

Featured Post

Comprehensive Backup Solutions for Microsoft

Acronis protects the complete Microsoft technology stack: Windows Server, Windows PC, laptop and Surface data; Microsoft business applications; Microsoft Hyper-V; Azure VMs; Microsoft Windows Server 2016; Microsoft Exchange 2016 and SQL Server 2016.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

OnPage: Incident management and secure messaging on your smartphone
Smart phones, smart watches, Bluetooth-connected devices—the IoT is all around us. In this article, we take a look at the security implications of our highly connected world.
In this video, we discuss why the need for additional vertical screen space has become more important in recent years, namely, due to the transition in the marketplace of 4x3 computer screens to 16x9 and 16x10 screens (so-called widescreen format). …
With the advent of Windows 10, Microsoft is pushing a Get Windows 10 icon into the notification area (system tray) of qualifying computers. There are many reasons for wanting to remove this icon. This two-part Experts Exchange video Micro Tutorial s…

685 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question