I am stumped at what is causing administrator lockout, open to ideas/suggestions as to what is causing it. Our syslog alerts us when accounts are locked out after a certain amount of times. I turned on debugging (nltest /dbflag:0x2080ffff) and installed netwrix but I am unable to determine what is causing it.
Debug log says this is coming from this system yet there are no services that are set to logon as the domain administrator, no mapped drives, pretty sure it's none of these scheduled tasks
TaskName Next Run Time Status======================================== ====================== ===============Password expiration report 8/10/2016 7:30:11 AM ReadyFolder: \MicrosoftTaskName Next Run Time Status======================================== ====================== ===============INFO: There are no scheduled tasks presently available at your access level.Folder: \Microsoft\WindowsTaskName Next Run Time Status======================================== ====================== ===============INFO: There are no scheduled tasks presently available at your access level.Folder: \Microsoft\Windows\Active Directory Rights Management Services ClientTaskName Next Run Time Status======================================== ====================== ===============AD RMS Rights Policy Template Management DisabledAD RMS Rights Policy Template Management N/A ReadyFolder: \Microsoft\Windows\AppIDTaskName Next Run Time Status======================================== ====================== ===============PolicyConverter DisabledVerifiedPublisherCertStoreCheck DisabledFolder: \Microsoft\Windows\Application ExperienceTaskName Next Run Time Status======================================== ====================== ===============AitAgent 8/9/2016 2:30:00 AM ReadyProgramDataUpdater 8/9/2016 12:30:00 AM ReadyFolder: \Microsoft\Windows\AutochkTaskName Next Run Time Status======================================== ====================== ===============Proxy N/A ReadyFolder: \Microsoft\Windows\CertificateServicesClientTaskName Next Run Time Status======================================== ====================== ===============SystemTask N/A ReadyUserTask N/A ReadyUserTask-Roam DisabledFolder: \Microsoft\Windows\Customer Experience Improvement ProgramTaskName Next Run Time Status======================================== ====================== ===============Consolidator 8/8/2016 6:00:00 PM Could not startKernelCeipTask 8/11/2016 3:30:00 AM ReadyUsbCeip 8/11/2016 1:30:00 AM ReadyFolder: \Microsoft\Windows\Customer Experience Improvement Program\ServerTaskName Next Run Time Status======================================== ====================== ===============ServerCeipAssistant 8/9/2016 10:57:57 PM Could not startServerRoleCollector 8/11/2016 12:50:44 AM ReadyServerRoleUsageCollector 8/9/2016 11:47:06 PM Could not startFolder: \Microsoft\Windows\DefragTaskName Next Run Time Status======================================== ====================== ===============ScheduledDefrag 8/10/2016 1:42:31 AM ReadyFolder: \Microsoft\Windows\MemoryDiagnosticTaskName Next Run Time Status======================================== ====================== ===============CorruptionDetector N/A ReadyDecompressionFailureDetector N/A ReadyFolder: \Microsoft\Windows\MUITaskName Next Run Time Status======================================== ====================== ===============LPRemove N/A ReadyFolder: \Microsoft\Windows\MultimediaTaskName Next Run Time Status======================================== ====================== ===============SystemSoundsService DisabledFolder: \Microsoft\Windows\NetTraceTaskName Next Run Time Status======================================== ====================== ===============GatherNetworkInfo N/A ReadyFolder: \Microsoft\Windows\PLATaskName Next Run Time Status======================================== ====================== ===============INFO: There are no scheduled tasks presently available at your access level.Folder: \Microsoft\Windows\Power Efficiency DiagnosticsTaskName Next Run Time Status======================================== ====================== ===============AnalyzeSystem 8/16/2016 7:34:22 AM ReadyFolder: \Microsoft\Windows\RACTaskName Next Run Time Status======================================== ====================== ===============RacTask 8/8/2016 3:10:22 PM ReadyFolder: \Microsoft\Windows\RasTaskName Next Run Time Status======================================== ====================== ===============MobilityManager N/A ReadyFolder: \Microsoft\Windows\RegistryTaskName Next Run Time Status======================================== ====================== ===============RegIdleBackup 8/16/2016 12:16:17 AM ReadyFolder: \Microsoft\Windows\Server ManagerTaskName Next Run Time Status======================================== ====================== ===============ServerManager N/A ReadyFolder: \Microsoft\Windows\SoftwareProtectionPlatformTaskName Next Run Time Status======================================== ====================== ===============SvcRestartTask DisabledFolder: \Microsoft\Windows\Task ManagerTaskName Next Run Time Status======================================== ====================== ===============Interactive N/A ReadyFolder: \Microsoft\Windows\TcpipTaskName Next Run Time Status======================================== ====================== ===============IpAddressConflict1 N/A ReadyIpAddressConflict2 N/A ReadyFolder: \Microsoft\Windows\TextServicesFrameworkTaskName Next Run Time Status======================================== ====================== ===============MsCtfMonitor N/A RunningFolder: \Microsoft\Windows\Time SynchronizationTaskName Next Run Time Status======================================== ====================== ===============SynchronizeTime 8/14/2016 1:00:00 AM ReadyFolder: \Microsoft\Windows\UPnPTaskName Next Run Time Status======================================== ====================== ===============UPnPHostConfig N/A ReadyFolder: \Microsoft\Windows\User Profile ServiceTaskName Next Run Time Status======================================== ====================== ===============HiveUploadTask DisabledFolder: \Microsoft\Windows\WDITaskName Next Run Time Status======================================== ====================== ===============ResolutionHost N/A ReadyFolder: \Microsoft\Windows\Windows Error ReportingTaskName Next Run Time Status======================================== ====================== ===============QueueReporting N/A ReadyFolder: \Microsoft\Windows\Windows Filtering PlatformTaskName Next Run Time Status======================================== ====================== ===============BfeOnServiceStartTypeChange N/A ReadyFolder: \Microsoft\Windows\WindowsColorSystemTaskName Next Run Time Status======================================== ====================== ===============Calibration Loader DisabledFolder: \Microsoft\Windows\WininetTaskName Next Run Time Status======================================== ====================== ===============CacheTask N/A Running
Are you logged on as the local computer's administrator when you check the Scheduled Tasks history?
stlhost
ASKER
Logged in as the domain administrator. Thought there was no local administrator account when it is running active directory?
awed1
stlhost, Well I kind of wondered how it could be possible, but thought I'd ask. There was a KB2549079 problem that had earmarks for what you are experiencing. It said that if you were logging on to look at the Scheduled Tasks history, with a local account that had the same name as your domain account, (administrator, and administrator) it would try and log you on with he domain account of that name. It came up, so I thought I'd ask.
stlhost, If it helps, your Event Log says that it is a bad password that is being used to try and log in on the administrator account:
C000006A user name is correct but the password is wrong
Maybe you had changed the password and some scheduled event still carries the old password etc.
stlhost
ASKER
The password was changed about a year ago. The account lockouts have always been an issue it's just getting worst as time goes by. So instead of a few events starting out, we're seeing up to 100 a day.
stlhost
ASKER
And actually when the alerts come to me from netwrix Ive noticed both domain controllers are showing up in the alerts not just one. If replication is failing would this cause it?
Who Changed domain\CTCDC2$
Where Changed ctcdc2.domain
Object Name \local\domain\Users\Administrator
Details User Account Locked Out
Who Changed domain\CTCDC1$
Where Changed ctcdc1.domain
Object Name \local\domain\Users\Administrator
Details User Account Locked Out
jenkinsgroup
Expert Comment
on 2008-03-11 at 18:24:49ID: 21102246
To add to this question because this is where we ended up when we had a very similar problem.
Go into DHCP > Right click server (in our case the PDC emu was the only DHCP server) and go Properties > Advanced Tab > "DNS Dynamic updates registration credentials"
Check if this is referencing the old admin password. This was what was locking our admin account after a password change. Took us a month of constant lockouts before we stumbled upon it by accident.
___________ someone else actually reported that this comment helped them ________
Several people also suggested that you look at all of the services set up to logon with the admin credentials to see if one of them was trying to use the wrong (old ?) password.
Additionally, several people pointed to a time discrepancy between the servers. That would have something to do with Kerberos attempting and failing etc.
I know that these are just ideas that you have probably looked at before, but here they are just in case one may help.
I ended up turning on diagnostics for active directory but the events were still being generated from what appeared to be only the domain controllers. In the end I turned on group policy audit logging and this gave me extra info and it turned out to be the nessus scanner that was causing it.