Re: Account Lockout Problems

From: Mark Renoden [MSFT] (markreno_at_online.microsoft.com)
Date: 11/18/04


Date: Fri, 19 Nov 2004 09:16:29 +1100

Hi Randy

My preferred method for tracking down these issues is as follows:

1. Use lockoutstatus.exe to identify which DC's the bad attempts are being
sent to.

2. Enable auditing on these DC's to catch the bad attempts and identify the
clients from which the bad attempts are originating. (see the document you
made reference to). You might skip step 1 and just enable auditing on all
DC's if it's a small environment. The frequency of the bad attempts will
indicate whether this is process related or the users just making a mistake.
Many in the same second ... process.

3. Based on frequency, if it looks process related, use ALockout.dll on the
client machines identified by the audit logs. The resulting log should tell
you what's responsible. If it's user related, fix the user ;)

What does your lockout policy look like? Are you following the guidance in
the article you've pointed to?

Kind regards

-- 
Mark Renoden [MSFT]
Windows Platform Support Team
Email: markreno@online.microsoft.com
Please note you'll need to strip ".online" from my email address to email 
me; I'll post a response back to the group.
This posting is provided "AS IS" with no warranties, and confers no rights.
"aubuchonz" <aubuchonz@discussions.microsoft.com> wrote in message 
news:1010CD72-4EE6-4828-8257-41BF679D6F09@microsoft.com...
>
> I am haveing some account lockout problems I can't seem to figure out. I
> have read the technet article
> http://www.microsoft.com/technet/prodtechnol/windowsserver2003/technologies/security/bpactlck.mspx.
> I have installed ALockout.dll and have netlogon logging.  The Logs don't
> make any sense to me.  The netlogon logs is nothing but mailslot entries.
> ALockout logs seem to list process when the lockout occurs but which ones 
> are
> important.  I see MS office entries and Lotus notes entries.  The only 
> thing
> these workstations have in common is they map to exteral domain drives 
> with a
> password.  I did clear reoccuring drives.  Thanks if this is not the right
> group for my question please point me in the right direction.  Thanks in
> advance, I find this forum very helpful.
>
> -- 
> Randy AuBuchon MCSE 2000 CISSP 


Relevant Pages

  • Re: Odd semi-crash or hang
    ... More details after reboot. ... Cannot find anything specific in logs, ... are some odd entries earlier this morning, ... Trying to reach it through remote desktop, ...
    (microsoft.public.windows.server.sbs)
  • Re: Determine When a User Logged In
    ... The Run entries in HKLM are executed for every user that logs in, ... Special privileges assigned to new logon: ...
    (microsoft.public.vb.general.discussion)
  • Re: Help with a shell script
    ... > I have about a years worth of text logs that have the following format: ... > I need to change the entries in the file to be semicolon separated. ... So your sed command file will look something like this, ...
    (comp.unix.shell)
  • Re: my log files-is there any problem
    ... >I am little concerned with these 2 means are these the normal entries ... >root 313 times isn't it too much. ... For the sendmail logs, nothing much to worry as a relaying attempt was ...
    (Fedora)
  • Re: slow slow windows start up
    ... No errorshould exist in either System or the Application logs. ... There will always be Informational type entries, ... It has the same layout as Windows ... >> time Left Click System Then look in the Right Pane ...
    (microsoft.public.windowsxp.general)