?
Solved

AD Account Keeps Getting Locked pt 2

Posted on 2015-02-04
2
Medium Priority
?
246 Views
Last Modified: 2015-02-05
I've been running into a problem recently that my AD account keeps getting locked out.  The lock is coming from three different computers, but so far, only those three - as indicated by event ID 4740 on our AD controller.  The lock out is occurring several times per day, but I haven't been able to identify a pattern.

These are computers that I rarely work with, and haven't touched any of them for at least a year (before investigating this issue) - one of them I've never worked on.  Also, all three aren't used much at all in daily use.


Event ID 14 on the suspect machines state that the password stored in credential manager is invalid.  That said, I have checked logged in both as local admin and myself and there are NO credentials stored in the Credential Manager.  Further, on all three machines, I have removed my local account from the registry - and I am still getting locked out.

So what is my next step?  This is driving me crazy.

TIA
0
Comment
Question by:Geisrud
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 2
2 Comments
 
LVL 14

Accepted Solution

by:
Geisrud earned 0 total points
ID: 40589845
I believe I found the answer.  Just want to post here for documentation and maybe it can help someone else.

https://social.technet.microsoft.com/Forums/windows/en-US/e1ef04fa-6aea-47fe-9392-45929239bd68/securitykerberos-event-id-14-credential-manager-causes-system-to-login-to-network-with-invalid?forum=w7itprosecurity




There are passwords that can be stored in the SYSTEM context that can't be seen in the normal Credential Manager view.

Download PsExec.exe from http://technet.microsoft.com/en-us/sysinternals/bb897553.aspx and copy it to C:\Windows\System32 .

From a command prompt run:    psexec -i -s -d cmd.exe

From the new DOS window run:  rundll32 keymgr.dll,KRShowKeyMgr

Remove any items that appear in the list of Stored User Names and Passwords.  Restart the computer.
0
 
LVL 14

Author Closing Comment

by:Geisrud
ID: 40591127
After waiting a while and confirming that my password is not locking out anymore, I'm convinced this is the fix I needed.  Hope this can help someone else too.
0

Featured Post

Industry Leaders: We Want Your Opinion!

We value your feedback.

Take our survey and automatically be enter to win anyone of the following:
Yeti Cooler, Amazon eGift Card, and Movie eGift Card!

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Uncontrolled local administrators groups within any organization pose a huge security risk. Because these groups are locally managed it becomes difficult to audit and maintain them.
This article provides a convenient collection of links to Microsoft provided Security Patches for operating systems that have reached their End of Life support cycle. Included operating systems covered by this article are Windows XP,  Windows Server…
This tutorial will walk an individual through the steps necessary to join and promote the first Windows Server 2012 domain controller into an Active Directory environment running on Windows Server 2008. Determine the location of the FSMO roles by lo…
This tutorial will walk an individual through setting the global and backup job media overwrite and protection periods in Backup Exec 2012. Log onto the Backup Exec Central Administration Server. Examine the services. If all or most of them are stop…
Suggested Courses
Course of the Month13 days, 5 hours left to enroll

777 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question