Solved

User's email account locks up three times a day.

Posted on 2015-01-16
7
151 Views
Last Modified: 2015-01-20
This issue was reported to me by Helpdesk. I have no experience with Exchange, but only with AD management. I was wondering if the email account is locked, does that mean his Windows AD account is locked? If I unlock his AD account, does that unlock his Exchange email account?

How do I fix the issue where the user's account keep locking out? How would I look at audit logs, or check PCs or network shares he may be connected to? See attached screenshot about his AD account, seems interesting to me. Has anyone ever seen this (image attached)? If so, how can I fix this?
2015-01-16-16-10-44.png
0
Comment
Question by:joukiejouk
7 Comments
 

Author Comment

by:joukiejouk
ID: 40554895
Also, it would be nice if someone can recommend a tool that can track this. Perhaps a tool that will reduce the leg work.
0
 
LVL 53

Accepted Solution

by:
Will Szymkowski earned 300 total points
ID: 40555032
Exchange uses the active directory account for authentication. So if your AD account is locked out then so I your Exchange Mailbox.

Unlocking your AD account will allow access to your mailbox again.

Something that can lock an account out are...
-logged into other machines with applications open and they change there password.
-network drives that have cached passwords
-service accounts or scheduled tasks that have cached user passwords
-smart phones where the password is cached and the user update to a new password

From my experience this is usually caused by the user logged into another machine other than their own, and forgetting to log off or close applications. Another one that is common is smart phone email access because you have to have the password cached on the phone.

A great tool to use and I would highly recommend is AD Audit Plus.

AD Audit Plus


Will.
0
 
LVL 69

Expert Comment

by:Qlemo
ID: 40555329
Security Event Log should show the attempts. Devices are sometimes logged with it, in any case you get a timestamp and might be able to narrow down based on that.
0
Problems using Powershell and Active Directory?

Managing Active Directory does not always have to be complicated.  If you are spending more time trying instead of doing, then it's time to look at something else. For nearly 20 years, AD admins around the world have used one tool for day-to-day AD management: Hyena. Discover why

 

Author Comment

by:joukiejouk
ID: 40555803
How do I find out what machines the user may have a session on? How do i troubleshoot if there is a network session the user might have open?
0
 

Author Comment

by:joukiejouk
ID: 40555883
Also, the unlock account option is grayed out. Why is this? I cannot unlock his account.
0
 
LVL 4

Assisted Solution

by:Praveen Kumar Bonala
Praveen Kumar Bonala earned 200 total points
ID: 40558843
I am agreeing with willszymkowski,
Account lockout tool from Microsoft will help you in this regards, this tool assist you to find where user account get locked and from which  DC user get locked. Following link explains you more about this tool
http://www.microsoft.com/en-us/download/details.aspx?id=18465
0
 
LVL 53

Expert Comment

by:Will Szymkowski
ID: 40558848
Download and install AD Audit Plus. As soon as you install this and point it to your security logs on the Domain Controllers it will tell you exactly what computer/device it is being locked out on.

Once you know what machine it is, it is pretty easy from there to figure out why it is being locked out.

Will.
0

Featured Post

Are your AD admin tools letting you down?

Managing Active Directory can get complicated.  Often, the native tools for managing AD are just not up to the task.  The largest Active Directory installations in the world have relied on one tool to manage their day-to-day administration tasks: Hyena. Start your trial today.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

While rebooting windows server 2003 server , it's showing "active directory rebuilding indices please wait" at startup. It took a little while for this process to complete and once we logged on not all the services were started so another reboot is …
A project that enables an administrator to perform actions within a user session context not just at the time of login but any time later on day(s) or week(s) later.
The video tutorial explains the basics of the Exchange server Database Availability groups. The components of this video include: 1. Automatic Failover 2. Failover Clustering 3. Active Manager
how to add IIS SMTP to handle application/Scanner relays into office 365.

726 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question