Go Premium for a chance to win a PS4. Enter to Win

x
?
Solved

Windows 2008 SBS account lockout policy

Posted on 2016-10-17
4
Medium Priority
?
90 Views
Last Modified: 2016-10-21
I have been trying to disable the local account lockout policy on a Windows SBS 2008 but it still locks account upon bad passwords either by login window or by bad password entered via mobile devices or owa, I have set the feature as not defined and used gpupdate /force, but no luck the accounts still gets locked across the network, can someone help.

Thank you
-jdff
0
Comment
Question by:jdff
  • 2
4 Comments
 
LVL 11

Assisted Solution

by:Maclean
Maclean earned 1000 total points
ID: 41847570
You probably have conflicting group policies.
Check which policies are in use when logged in, and go through them all.
Disabling lockout policy is a bad idea however. As IT Admin I would in writing object to the request and list the reasons (Security etc)

There are alternatives to whatever issue there might be.
e.g. self unlock programs, or user education.
1
 
LVL 9

Accepted Solution

by:
Antzs earned 1000 total points
ID: 41847759
The lockout policy is a default security policy in Windows Domain.  I don't think there is anyway you can disable it.

You can always set the account options for the particular user account, so that the password cant be changed and the password does not expire.

If the account keeps on locking out, you need to find out the real reason why is this happening.
0
 

Author Comment

by:jdff
ID: 41848223
Maclean, I understand but at this moment I really need to get this feature disabled, this network has not incoming connection so it not a big deal at this point.
0
 
LVL 11

Assisted Solution

by:Maclean
Maclean earned 1000 total points
ID: 41849909
I respect whichever way one would want to go of course.
Merely advising of the risk.

Lockout policy is there not to protect only against external attackers, but also against internal misuse.
e.g. Joe Blogs in Payroll leaves computer running overnight, cleaners come in, and find an unlocked payroll PC with intruiging information, so they take the company "to the cleaners".

I have heard of this scenario happen from one of our clients (Happened before I looked after them)So keep things like that in mind is all I am saying. A lot of data theft occurs local onsite. Not external.
Unless the company has nothing of value that could be used to damage their reputation by losing confidential client data, or financial info on the firm itself, I'd always advocate leaving it turned on, and instead locating the source of the lockouts using Netwrix Lockout Examiner or the MS Logs/Tools.. Again though. Its just information I am providing :)

Anyway, back on point. If you want to disable it, check your group policies as suggested.
Go through them and find if there are more policies doing the same thing on the SBS.
There's bound to be a 2nd Policy doing the same thing as the original one you disabled.
Good luck :)
0

Featured Post

Vote for the Most Valuable Expert

It’s time to recognize experts that go above and beyond with helpful solutions and engagement on site. Choose from the top experts in the Hall of Fame or on the right rail of your favorite topic page. Look for the blue “Nominate” button on their profile to vote.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Possible fixes for Windows 7 and Windows Server 2008 updating problem. Solutions mentioned are from Microsoft themselves. I started a case with them from our Microsoft Silver Partner option to open a case and get direct support from Microsoft. If s…
This article provides a convenient collection of links to Microsoft provided Security Patches for operating systems that have reached their End of Life support cycle. Included operating systems covered by this article are Windows XP,  Windows Server…
This tutorial will show how to push an installation of Backup Exec to an additional server in both 2012 and 2014 versions of the software. Click on the Backup Exec button in the upper left corner. From here, select Installation and Licensing, then I…
This tutorial will walk an individual through the steps necessary to install and configure the Windows Server Backup Utility. Directly connect an external storage device such as a USB drive, or CD\DVD burner: If the device is a USB drive, ensure i…

926 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question