Unable to change Windows 2000 Account Lockout Policy

Tech-Archive recommends: Repair Windows Errors & Optimize Windows Performance

From: Wouter (wouterjorritsma_at_hotmail.com)
Date: 07/05/04


Date: 5 Jul 2004 06:22:46 -0700

I (or in fact, a customer of me) have a Windows 2000 Active Directory
domain divided into multiple sites. In this domain, there is a Default
Domain Security Policy active with an Account Lockout Policy. All
servers are Windows 2000 Server SP4.

This policy is set to an Account Lockout treshold of 5. This means
that an account will be locked out after 5 consecutive wrong
passwords. After 30 minutes, it will be unlocked or if you do this
manually of course. The problem is, that I can't change this Lockout
treshold of 5. As far as I know, the only place I have to change this
is in the Default Domain Security Policy so I changed the Lockout
treshold to 999 but no effect. Can wait until Christmas (even after
commands like 'secedit /refreshpolicy machine_policy /enforce' but
somehow, it won't change.

When I check it with the command 'net accounts', I get the following
info. As you can see, the lockout treshold is 5, although I configured
it to 999.

Screenshot: http://www.jw-racing.nl/public/lockout.jpg

After that, I ran gpresult.exe and got the following info:

===============================================================
The computer received "Registry" settings from these GPOs:

        Local Group Policy

===============================================================
The computer received "Security" settings from these GPOs:

        Local Group Policy
        Default Domain Controllers Policy

===============================================================
The computer received "EFS recovery" settings from these GPOs:

        Local Group Policy

I also checked (with gpedit.msc) the Local Group Policy and the
Default Domain Controllers Policy but they all aren't configured with
a Lockout Policy.

Then, I found this Knowledgebase article from Microsoft:
http://support.microsoft.com/default.aspx?scid=kb;EN-US;Q269236

It says that this behaviour is either caused by Block Policy
Inheritance being enabled or if the password policy is not set in the
Default Domain policy. This however, is in both cases not the problem.
I don't have this Block Policy Inheritance option enabled and the
password policy IS set in my Default Domain Policy.

I'm clueless, who can help me out? Whatever I try, the account lockout
policy won't change.

Thanks a lot! If you need more info, do not hesistate to ask.

Regards,

Wouter Jorritsma
The Netherlands



Relevant Pages

  • Re: OU group policy and how to use ldapsearch to find GPO settings
    ... To find the default domain policy settings, ... If I configure the account lockout policy in the default domain policy, ...
    (microsoft.public.windows.group_policy)
  • RE: 529 Logon Failures - 138 Events
    ... I am using complex passwords....I have not configured the lockout feature. ... Can I configure a lockout policy for the server itself? ... If I lock the server will I be able to unlock it to do maintenance? ... Configure account lockout policy. ...
    (microsoft.public.windows.server.sbs)
  • Re: Strong passwords and user locking?
    ... policy, associated it to my new OU and set the Account Lockout ... Lockout Counter After to 30 minutes. ... lockout settings and when I login as the test user it doesn't show this ...
    (microsoft.public.windows.server.security)
  • Unable to change Windows 2000 Account Lockout Policy
    ... Domain Security Policy active with an Account Lockout Policy. ... This policy is set to an Account Lockout treshold of 5. ...
    (microsoft.public.win2000.active_directory)
  • Re: Service Accounts & Account Lock out Policy
    ... Also I would say that 5 bads is extremely low and will likely be counterproductive and cause you more issues than it is worth. ... If you set the policy as low as 25 with a five minute lockout reset this should be more than adequate to prevent brute force attacks and not completely piss off your users when they fat finger. ... I don't want to this policy to apply to the Service accounts used by the applications as it will lock-out the service account and will stop it. ...
    (microsoft.public.security)