Re: active directory group locked

Tech Tip: Click here to run a free scan for Windows Errors and optimize PC performance



Accounts don't just lock, there is a reason, you simply don't know what it is. Kick up auditing of bad auth and start chasing through your DC event logs. If you look at the badpwdcount attribute on each DC, you should see which DC is fielding the bad attempts. Note that the PDC should be seeing the most bads as all bad's should be redirected to it.

Also note that 5 is ridiculously low for a lockout policy. Many interactive logon attempts will generate 3 bad auth attempts with a single interactive user logon attempt.

--
Joe Richards Microsoft MVP Windows Server Directory Services
Author of O'Reilly Active Directory Third Edition
www.joeware.net


---O'Reilly Active Directory Third Edition now available---

http://www.joeware.net/win/ad3e.htm



arrell@xxxxxxxxx wrote:
hi,

We in our company facing a problem of locked user accounts without a
known reason, we have a group policy if the user attempts wrong
password for more than 5 times it should have been locked and its
working with it fine, but there isnt any reason for locking accounts
without any reason. Please assist in this regard.

thanx

ArrEll

.



Relevant Pages

  • Re: IIS Security
    ... The main reason for granting ... Administrator privileges to accounts that don't need ... permissions that are really needed. ...
    (Focus-Microsoft)
  • Re: Battle.net account
    ... that that is the *only* thing the battle.net accounts seem to do. ... see no reason to do it before they make you do it. ... Eilnich (70 Blood Elf Warlock) ... Balgair (70 Human Rogue) ...
    (alt.games.warcraft)
  • Re: ready yet for M? [YACD]
    ... no reason you "have" to killfile them. ... Google Groups is glitchy and often some accounts are unable to post ... and switch to another one if one of them quits working. ... If Google Groups worked reliably, then I'd be able to stick with just ...
    (rec.games.roguelike.angband)
  • Passwords dont seem to work (on websites)
    ... I am having some difficulties using accounts and fill out ... passwords other times doesn't say anything, ... reason it doesn't go. ... there is a 4 digit code I must enter that appears on the ...
    (microsoft.public.windows.inetexplorer.ie6.browser)
  • Re: Minimum password requirements
    ... but this is based on my experiences with a variety ... This would be all admin accounts, ... reason they want to change the password every day I'd let them. ... Ripper/etc to audit the passwords on admin accounts (which is a mixed ...
    (Security-Basics)