Solved

AD Account Keeps Getting Locked pt 2

Posted on 2015-02-04
2
203 Views
Last Modified: 2015-02-05
I've been running into a problem recently that my AD account keeps getting locked out.  The lock is coming from three different computers, but so far, only those three - as indicated by event ID 4740 on our AD controller.  The lock out is occurring several times per day, but I haven't been able to identify a pattern.

These are computers that I rarely work with, and haven't touched any of them for at least a year (before investigating this issue) - one of them I've never worked on.  Also, all three aren't used much at all in daily use.


Event ID 14 on the suspect machines state that the password stored in credential manager is invalid.  That said, I have checked logged in both as local admin and myself and there are NO credentials stored in the Credential Manager.  Further, on all three machines, I have removed my local account from the registry - and I am still getting locked out.

So what is my next step?  This is driving me crazy.

TIA
0
Comment
Question by:Geisrud
  • 2
2 Comments
 
LVL 14

Accepted Solution

by:
Geisrud earned 0 total points
ID: 40589845
I believe I found the answer.  Just want to post here for documentation and maybe it can help someone else.

https://social.technet.microsoft.com/Forums/windows/en-US/e1ef04fa-6aea-47fe-9392-45929239bd68/securitykerberos-event-id-14-credential-manager-causes-system-to-login-to-network-with-invalid?forum=w7itprosecurity




There are passwords that can be stored in the SYSTEM context that can't be seen in the normal Credential Manager view.

Download PsExec.exe from http://technet.microsoft.com/en-us/sysinternals/bb897553.aspx and copy it to C:\Windows\System32 .

From a command prompt run:    psexec -i -s -d cmd.exe

From the new DOS window run:  rundll32 keymgr.dll,KRShowKeyMgr

Remove any items that appear in the list of Stored User Names and Passwords.  Restart the computer.
0
 
LVL 14

Author Closing Comment

by:Geisrud
ID: 40591127
After waiting a while and confirming that my password is not locking out anymore, I'm convinced this is the fix I needed.  Hope this can help someone else too.
0

Featured Post

Are your corporate email signatures appalling?

Is it scary how unprofessional your email signatures look? Do users create their own terrible designs and give themselves stupid job titles? You can make this a lot easier for yourself by choosing an email signature management solution from Exclaimer today.

Join & Write a Comment

Citrix XenApp, Internet Explorer 11 set to Enterprise Mode and using central hosted sites.xml file.
A safe way to clean winsxs folder from your windows server 2008 R2 editions
To efficiently enable the rotation of USB drives for backups, storage pools need to be created. This way no matter which USB drive is installed, the backups will successfully write without any administrative intervention. Multiple USB devices need t…
This tutorial will walk an individual through the steps necessary to install and configure the Windows Server Backup Utility. Directly connect an external storage device such as a USB drive, or CD\DVD burner: If the device is a USB drive, ensure i…

758 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

20 Experts available now in Live!

Get 1:1 Help Now