Still celebrating National IT Professionals Day with 3 months of free Premium Membership. Use Code ITDAY17

x
?
Solved

Windows 2008 SBS account lockout policy

Posted on 2016-10-17
4
Medium Priority
?
86 Views
Last Modified: 2016-10-21
I have been trying to disable the local account lockout policy on a Windows SBS 2008 but it still locks account upon bad passwords either by login window or by bad password entered via mobile devices or owa, I have set the feature as not defined and used gpupdate /force, but no luck the accounts still gets locked across the network, can someone help.

Thank you
-jdff
0
Comment
Question by:jdff
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 2
4 Comments
 
LVL 11

Assisted Solution

by:TS4B
TS4B earned 1000 total points
ID: 41847570
You probably have conflicting group policies.
Check which policies are in use when logged in, and go through them all.
Disabling lockout policy is a bad idea however. As IT Admin I would in writing object to the request and list the reasons (Security etc)

There are alternatives to whatever issue there might be.
e.g. self unlock programs, or user education.
1
 
LVL 9

Accepted Solution

by:
Antzs earned 1000 total points
ID: 41847759
The lockout policy is a default security policy in Windows Domain.  I don't think there is anyway you can disable it.

You can always set the account options for the particular user account, so that the password cant be changed and the password does not expire.

If the account keeps on locking out, you need to find out the real reason why is this happening.
0
 

Author Comment

by:jdff
ID: 41848223
Maclean, I understand but at this moment I really need to get this feature disabled, this network has not incoming connection so it not a big deal at this point.
0
 
LVL 11

Assisted Solution

by:TS4B
TS4B earned 1000 total points
ID: 41849909
I respect whichever way one would want to go of course.
Merely advising of the risk.

Lockout policy is there not to protect only against external attackers, but also against internal misuse.
e.g. Joe Blogs in Payroll leaves computer running overnight, cleaners come in, and find an unlocked payroll PC with intruiging information, so they take the company "to the cleaners".

I have heard of this scenario happen from one of our clients (Happened before I looked after them)So keep things like that in mind is all I am saying. A lot of data theft occurs local onsite. Not external.
Unless the company has nothing of value that could be used to damage their reputation by losing confidential client data, or financial info on the firm itself, I'd always advocate leaving it turned on, and instead locating the source of the lockouts using Netwrix Lockout Examiner or the MS Logs/Tools.. Again though. Its just information I am providing :)

Anyway, back on point. If you want to disable it, check your group policies as suggested.
Go through them and find if there are more policies doing the same thing on the SBS.
There's bound to be a 2nd Policy doing the same thing as the original one you disabled.
Good luck :)
0

Featured Post

Free Backup Tool for VMware and Hyper-V

Restore full virtual machine or individual guest files from 19 common file systems directly from the backup file. Schedule VM backups with PowerShell scripts. Set desired time, lean back and let the script to notify you via email upon completion.  

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

A safe way to clean winsxs folder from your windows server 2008 R2 editions
I was prompted to write this article after the recent World-Wide Ransomware outbreak. For years now, System Administrators around the world have used the excuse of "Waiting a Bit" before applying Security Patch Updates. This type of reasoning to me …
This tutorial will walk an individual through the steps necessary to install and configure the Windows Server Backup Utility. Directly connect an external storage device such as a USB drive, or CD\DVD burner: If the device is a USB drive, ensure i…
This tutorial will walk an individual through the steps necessary to join and promote the first Windows Server 2012 domain controller into an Active Directory environment running on Windows Server 2008. Determine the location of the FSMO roles by lo…

715 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question