• Status: Solved
  • Priority: Medium
  • Security: Public
  • Views: 500
  • Last Modified:

Audit Failure and Account Lockouts - Active Directory

I have a SBS 2011 Server and currently issues with account lockouts and Audit failures. All users use Exchange Active Synch, RWW and OWA. The login attempt originating externally and I have trouble resolving the issue. I have attempted to block the external IP address in the firewall but does not seem to make a difference. Any help is very much appreciated. Below the audit failure details.
Security ID:            SYSTEM
      Account Name:            TLWSVR$
      Account Domain:            TLW
      Logon ID:            0x3e7

Logon Type:                  8

Account For Which Logon Failed:
      Security ID:            NULL SID
      Account Name:            sue
      Account Domain:            tlw

Failure Information:
      Failure Reason:            Unknown user name or bad password.
      Status:                  0xc000006d
      Sub Status:            0xc000006a

Process Information:
      Caller Process ID:      0x23c8
      Caller Process Name:      C:\Windows\System32\inetsrv\w3wp.exe

Network Information:
      Workstation Name:      TLWSVR
      Source Network Address:
      Source Port:            15060

Detailed Authentication Information:
      Logon Process:            Advapi  
      Authentication Package:      Negotiate
      Transited Services:      -
      Package Name (NTLM only):      -
      Key Length:            0
1 Solution
Simon Butler (Sembee)ConsultantCommented:
My instinct would be that the user has entered their password somewhere - mobile device most likely. The password has then been changed on the account but the device hasn't been updated.

If it happening to multiple users, then someone is doing an authentication attack. The address belongs to the Australian ISP Telstra. I presume it isn't your address?

You could use IP address restrictions on IIS to block that address if it is constantly the same address.

co_olAuthor Commented:
I was unable to determine who that ip address belongs to but was able to block that ip address. Unless someone complains about unable to access the server i assume it is an unauthorized access. Thanks
Question has a verified solution.

Are you are experiencing a similar issue? Get a personalized answer when you ask a related question.

Have a better answer? Share it in a comment.

Join & Write a Comment

Featured Post

Easily manage email signatures in Office 365

Managing email signatures in Office 365 can be a challenging task if you don't have the right tool. CodeTwo Email Signatures for Office 365 will help you implement a unified email signature look, no matter what email client is used by users. Test it for free!

Tackle projects and never again get stuck behind a technical roadblock.
Join Now