?
Solved

User's email account locks up three times a day.

Posted on 2015-01-16
7
Medium Priority
?
154 Views
Last Modified: 2015-01-20
This issue was reported to me by Helpdesk. I have no experience with Exchange, but only with AD management. I was wondering if the email account is locked, does that mean his Windows AD account is locked? If I unlock his AD account, does that unlock his Exchange email account?

How do I fix the issue where the user's account keep locking out? How would I look at audit logs, or check PCs or network shares he may be connected to? See attached screenshot about his AD account, seems interesting to me. Has anyone ever seen this (image attached)? If so, how can I fix this?
2015-01-16-16-10-44.png
0
Comment
Question by:joukiejouk
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
7 Comments
 

Author Comment

by:joukiejouk
ID: 40554895
Also, it would be nice if someone can recommend a tool that can track this. Perhaps a tool that will reduce the leg work.
0
 
LVL 53

Accepted Solution

by:
Will Szymkowski earned 900 total points
ID: 40555032
Exchange uses the active directory account for authentication. So if your AD account is locked out then so I your Exchange Mailbox.

Unlocking your AD account will allow access to your mailbox again.

Something that can lock an account out are...
-logged into other machines with applications open and they change there password.
-network drives that have cached passwords
-service accounts or scheduled tasks that have cached user passwords
-smart phones where the password is cached and the user update to a new password

From my experience this is usually caused by the user logged into another machine other than their own, and forgetting to log off or close applications. Another one that is common is smart phone email access because you have to have the password cached on the phone.

A great tool to use and I would highly recommend is AD Audit Plus.

AD Audit Plus


Will.
0
 
LVL 70

Expert Comment

by:Qlemo
ID: 40555329
Security Event Log should show the attempts. Devices are sometimes logged with it, in any case you get a timestamp and might be able to narrow down based on that.
0
VIDEO: THE CONCERTO CLOUD FOR HEALTHCARE

Modern healthcare requires a modern cloud. View this brief video to understand how the Concerto Cloud for Healthcare can help your organization.

 

Author Comment

by:joukiejouk
ID: 40555803
How do I find out what machines the user may have a session on? How do i troubleshoot if there is a network session the user might have open?
0
 

Author Comment

by:joukiejouk
ID: 40555883
Also, the unlock account option is grayed out. Why is this? I cannot unlock his account.
0
 
LVL 4

Assisted Solution

by:Praveen Kumar Bonala
Praveen Kumar Bonala earned 600 total points
ID: 40558843
I am agreeing with willszymkowski,
Account lockout tool from Microsoft will help you in this regards, this tool assist you to find where user account get locked and from which  DC user get locked. Following link explains you more about this tool
http://www.microsoft.com/en-us/download/details.aspx?id=18465
0
 
LVL 53

Expert Comment

by:Will Szymkowski
ID: 40558848
Download and install AD Audit Plus. As soon as you install this and point it to your security logs on the Domain Controllers it will tell you exactly what computer/device it is being locked out on.

Once you know what machine it is, it is pretty easy from there to figure out why it is being locked out.

Will.
0

Featured Post

Is Your AD Toolbox Looking More Like a Toybox?

Managing Active Directory can get complicated.  Often, the native tools for managing AD are just not up to the task.  The largest Active Directory installations in the world have relied on one tool to manage their day-to-day administration tasks: Hyena. Start your trial today.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Unified and professional email signatures help maintain a consistent company brand image to the outside world. This article shows how to create an email signature in Exchange Server 2010 using a transport rule and how to overcome native limitations …
There are times when we need to generate a report on the inbox rules, where users have set up forwarding externally in their mailbox. In this article, I will be sharing a script I wrote to generate the report in CSV format.
The basic steps you have just learned will be implemented in this video. The basic steps are shown to configure an Exchange DAG in a live working Exchange Server Environment and manage the same (Exchange Server 2010 Software is used in a Windows Ser…
Michael from AdRem Software explains how to view the most utilized and worst performing nodes in your network, by accessing the Top Charts view in NetCrunch network monitor (https://www.adremsoft.com/). Top Charts is a view in which you can set seve…
Suggested Courses
Course of the Month14 days, 22 hours left to enroll

770 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question