Re: Accounts lockout policy not working as expected

From: Gary Mudgett [MSFT] (garymu_at_online.microsoft.com)
Date: 07/14/04


Date: Wed, 14 Jul 2004 12:44:32 -0400

This is actually by design. The GUI is not updated until the user actually
gets a successful logon after the 15 minutes have passed. As long as the
period has passed AD will treat the account as unlocked.

Are you saying that even after 15+ minutes has passed the user is not able
to logon successfully without an administrator unlocking the account?

Also, to ensure that the domain controller has these settings as effected
you could run "net accounts" at a command prompt and view the output.

-- 
Gary Mudgett, MCSE, MCSA
Windows 2000/2003 Directory Services
=====================================================
When responding to posts, please "Reply to Group" via
your newsreader so that others may learn and benefit
from your issue.
=====================================================
This posting is provided "AS IS" with no warranties, and confers no rights.
"Nathan H" <anonymous@discussions.microsoft.com> wrote in message
news:uLKCJQbaEHA.1048@tk2msftngp13.phx.gbl...
> Hi Janet
>
> > On the "Default Domain Policy" I have the following set:
> >
> > Account Lockout Duration: 15 minutes
> > Account Lockout Threshold: 5 bad logon attempts
> > Reset Account Lockout counter: 10 minutes
> >
> > If someone enters 5 bad passwords their account indeed becomes locked
out,
> > but the account never automatically unlocks again. It always has to be
> > manually unlocked no matter how long I wait.  How can I get the account
to
> > automatically unlock itself?
>
> ahhh...someone with similar lockout problems....see my post on it called:
>
> User log on lock out policy does not function correctly in 2003
>
> I forgot that this happens also to me.....once locked out, they stay
locked
> out too :(
>
> Here though, they only have to get it wrong (or in some cases, even when
> getting
> it right) once for it to lock them out permanently.
>
> Regards and please post if you find anything out.
>
>
> -- 
> Nathan Harmsworth
> IT / Network Administrator
> Ysgol Bro Ddyfi (Edu)
>
>


Relevant Pages

  • RE: Limit number of Logon attempts
    ... I understand that you want to adjust the logon attempts through Group ... we have an Account Lockout policy ...
    (microsoft.public.windows.server.sbs)
  • Re: Security Event Log missing entries
    ... There is a difference between account logon and logon events. ... --- good MS white paper on account lockout policy. ...
    (microsoft.public.win2000.security)
  • Re: IIS5 Integrated Windows Authentication prompts password
    ... Set your "Reset account lockout counter after" to 5 minute ... > Start auditing for failed logon attempts. ... >: Event Type: Failure Audit ...
    (microsoft.public.inetserver.iis.security)
  • Re: sol 10 passwd expiration
    ... My question pertains to the ... also updated when a user's account is locked (i.e. from three failed ... question -- Is there anyway to keep the passwd expiration date the same ... after unlocking a user account? ...
    (comp.sys.sun.admin)
  • Re: New columns in V$yablespace
    ... For the first question, please refer to the online documentation at ... unlocking an account is a permanent operation. ... It won't be locked again when you restart the database. ...
    (comp.databases.oracle.misc)