Re: DC in remote site locking one user account

Tech Tip: Click here to run a free scan for Windows Errors and optimize PC performance



In news:3FE04001-9FAD-413E-815B-0D25A0DFE1C3@xxxxxxxxxxxxx,
Rob Taylor <RobTaylor@xxxxxxxxxxxxxxxxxxxxxxxxx> made this post, which I
then commented about below:
> I have a funny issue where one of my Domain Controllers is locking a
> user account over and over.
>
> Config:
> I have a simple three site config with one domain controller in each
> site.
> I know...we could use some additional domain controllers...but money
> is tight. Let's call the three sites: Site-A, Site-B and Site-C.
> Respectively we have DC-A, DC-B, and DC-C. I have determined DC-C is
> the server having the issue. All DCs are running 2003 SP1. The user
> works in Site-A.
>
>
> I have researched/tried the following to remedy the issue:
>
> I am certain the user does not have an active session with an old
> password on any Terminal Servers in use.
>
> I have tried resetting the user account and password directly on each
> domain controller in the domain.
>
> I have tried setting the password to never expire.
>
> I have disabled and re-enabled the user account. These changed all
> get replicated properly. Replication tests all seem to work properly.
>
> I have noticed that unlocking the user account on DC-C only works
> briefly (1-20 seconds) before the server locks it again. I have also
> noticed that if I reset the account continuously on DC-C I can
> prevent the user account from being locked out on all other DCs. This
> is not how I like to spend my day, but it proves that DC-C is the
> source of the problem. It appears DC-C has a corrupt copy of the AD
> dB or at least this user's entry in the AD dB on DC-C is partially
> corrupt.
>
> Anyway...I have also tried the following trick:
>
> I made a copy of the user account and deleted the original and then I
> confirmed the original user account was no longer stored on any of
> the other Domain Controllers and then I tried re-creating the user
> account as it was by making a copy of the copy but using all of the
> same original user info. As soon as I re-created the account....DC-C
> started locking it up again. Talk about frustrating!
>
> So I am throwing this question to you.... How I fix this? Do I need
> to run ADSI edit and make some weird change for this user? What
> other steps can I take?

Just a guess, but it sounds like a service or app is using the account for
startup logon and the password was changed on the account, but not in the
service or app. Unless someone's hammering it one way or another or coming
thru a website on the machine or in the domain, such as maybe OWA. Put it
this way, it's being locked because something is trying to use it. Any app
or service won't use the SID to lookup the account, that's just for
accessing resourses and domain authentication functionality, so that's why
it locks up again, it's using the logon alias.

--
Regards,
Ace

Please direct all replies ONLY to the Microsoft public newsgroups
so all can benefit.

This posting is provided "AS-IS" with no warranties or guarantees
and confers no rights.

Ace Fekay, MCSE 2003 & 2000, MCSA 2003 & 2000, MCSE+I, MCT, MVP
Microsoft Windows MVP - Windows Server - Directory Services
Infinite Diversities in Infinite Combinations.
=================================


.



Relevant Pages

  • Re: Problems with user lockout TS Administrative Mode
    ... MCSE, CCEA, Microsoft MVP - Terminal Server ... My user account gets locked out and once I ... > There are Failure Audits originating from this server's IP ... > address on my user account on one of the domain controllers. ...
    (microsoft.public.windows.terminal_services)
  • Re: Policy mismatch, but I dont see it
    ... Create a test user account object but do not mail-enable it....just create ... I put that .txt file in the SYSVOL shared folder of DC01. ... Domain Controllers in the Domain. ... Both are subject to their replication cycles ( ...
    (microsoft.public.win2000.group_policy)
  • Re: 2008 Domain Upgrade - Schema Mismatch
    ... MCSE, MVP Directory Services ... All domain controllers are global catalog ... > launch AD Sites and Services and attempt to force in-bound replication ... The user account was fortunately a long disabled user so I ...
    (microsoft.public.windows.server.active_directory)
  • Problems with user lockout TS Administrative Mode
    ... One Server that is a Member Server with SQL Database started locking out my ... There are Failure Audits originating from this server's IP address on my ... user account on one of the domain controllers. ...
    (microsoft.public.windows.terminal_services)
  • Re: DC in remote site locking one user account
    ... The user account is strictly for their use and is ... I determined it is DC-C that is causing the problem. ... >> briefly before the server locks it again. ... >> the other Domain Controllers and then I tried re-creating the user ...
    (microsoft.public.windows.server.active_directory)