We help IT Professionals succeed at work.

Domain Administrator locked out "Again"

186 Views
Last Modified: 2018-05-10
I posted this question previously and was able to solve it using Netwrix account lockout.  This time I can't solve it.  When I unlock his account, with in 1 minute it locks again.  He is connecting from Long Beach to Los Angeles.  He is completely logged off of his computer as of this posting, put his still getting locked out.
It previously stated his password was bad 3 times.   Now it shows 0 for bad password, but within a minute he is locked out.  See image.   In the image it shows he is connected from Workstation FreeRDP.   I have no idea what that is.

HELP!
locked out
Comment
Watch Question

Dr. KlahnPrincipal Software Engineer
CERTIFIED EXPERT

Commented:
At first glance it looks like this account is being targeted by a hacker.

For diagnosis, you might try:  Generate a new account for the user with a completely different name and disable the old account.

If the problem then follows to the new account, there may be a security problem on the user's computer that is exposing network credentials but not passwords.  Scan that system aggressively with whatever antivirus is on it, use a couple of the online antiviruses as well, run Malwarebytes against it, and Spybot - Search and Destroy.

If the problem does not follow to the new account, it may still be a hostile attempting to gain access but the user's computer is less likely to be aiding the attempt.
J.R. SitmanIT Director

Author

Commented:
He is not logged on to any computer at this location and he is only getting locked out from one DC.
Tom CieslikIT Engineer
CERTIFIED EXPERT
Distinguished Expert 2017

Commented:
Try rename domain admin account to different one or create another domain user and assign him Domanin Admin rights.
Then this will give you more time.
You can enable audit in your domain and check DC security log to find out from what place lock out is coming.
Senior Consultant
CERTIFIED EXPERT
Awarded 2017
Distinguished Expert 2019
Commented:
Unlock this solution and get a sample of our free trial.
(No credit card required)
UNLOCK SOLUTION
J.R. SitmanIT Director

Author

Commented:
@Shaun your article is very good.  I was able to pin point the server causing the lockout.
E ATech Lead
CERTIFIED EXPERT

Commented:
J.R. SitmanIT Director

Author

Commented:
@Kevin.  Thanks also very helpful
Unlock the solution to this question.
Thanks for using Experts Exchange.

Please provide your email to receive a sample view!

*This site is protected by reCAPTCHA and the Google Privacy Policy and Terms of Service apply.

OR

Please enter a first name

Please enter a last name

8+ characters (letters, numbers, and a symbol)

By clicking, you agree to the Terms of Use and Privacy Policy.