Solved

AD Account Keeps Getting Locked pt 2

Posted on 2015-02-04
2
216 Views
Last Modified: 2015-02-05
I've been running into a problem recently that my AD account keeps getting locked out.  The lock is coming from three different computers, but so far, only those three - as indicated by event ID 4740 on our AD controller.  The lock out is occurring several times per day, but I haven't been able to identify a pattern.

These are computers that I rarely work with, and haven't touched any of them for at least a year (before investigating this issue) - one of them I've never worked on.  Also, all three aren't used much at all in daily use.


Event ID 14 on the suspect machines state that the password stored in credential manager is invalid.  That said, I have checked logged in both as local admin and myself and there are NO credentials stored in the Credential Manager.  Further, on all three machines, I have removed my local account from the registry - and I am still getting locked out.

So what is my next step?  This is driving me crazy.

TIA
0
Comment
Question by:Geisrud
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 2
2 Comments
 
LVL 14

Accepted Solution

by:
Geisrud earned 0 total points
ID: 40589845
I believe I found the answer.  Just want to post here for documentation and maybe it can help someone else.

https://social.technet.microsoft.com/Forums/windows/en-US/e1ef04fa-6aea-47fe-9392-45929239bd68/securitykerberos-event-id-14-credential-manager-causes-system-to-login-to-network-with-invalid?forum=w7itprosecurity




There are passwords that can be stored in the SYSTEM context that can't be seen in the normal Credential Manager view.

Download PsExec.exe from http://technet.microsoft.com/en-us/sysinternals/bb897553.aspx and copy it to C:\Windows\System32 .

From a command prompt run:    psexec -i -s -d cmd.exe

From the new DOS window run:  rundll32 keymgr.dll,KRShowKeyMgr

Remove any items that appear in the list of Stored User Names and Passwords.  Restart the computer.
0
 
LVL 14

Author Closing Comment

by:Geisrud
ID: 40591127
After waiting a while and confirming that my password is not locking out anymore, I'm convinced this is the fix I needed.  Hope this can help someone else too.
0

Featured Post

Back Up Your Microsoft Windows Server®

Back up all your Microsoft Windows Server – on-premises, in remote locations, in private and hybrid clouds. Your entire Windows Server will be backed up in one easy step with patented, block-level disk imaging. We achieve RTOs (recovery time objectives) as low as 15 seconds.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

This article demonstrates probably the easiest way to configure domain-wide tier isolation within Active Directory. If you do not know tier isolation read https://technet.microsoft.com/en-us/windows-server-docs/security/securing-privileged-access/s…
Always backup Domain, SYSVOL etc.using processes according to Microsoft Best Practices. This is meant as a disaster recovery process for small environments that did not implement backup processes and did not run a secondary domain controller that ne…
This tutorial will walk an individual through the steps necessary to enable the VMware\Hyper-V licensed feature of Backup Exec 2012. In addition, how to add a VMware server and configure a backup job. The first step is to acquire the necessary licen…
This tutorial will walk an individual through the process of transferring the five major, necessary Active Directory Roles, commonly referred to as the FSMO roles from a Windows Server 2008 domain controller to a Windows Server 2012 domain controlle…

763 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question