Re: How to find where a username is trying to log on from

Tech Tip: Click here to run a free scan for Windows Errors and optimize PC performance



Is the account logged into more than one machine or is it running a service
on the same machine? A user could have mapped drives to a resource from one
machine, on a different machine he changes his password and then the first
machine attempts to stay mapped to a drive and the password is no longer
correct and eventually locks the user out. Or after a password is changed a
service is running that attempts to authenticate with an old password.

To help try and track down where the account is getting locked out use
eventcombMT.exe from the Account Lockout tools found out Microsoft's
website. Use the built in search AccountLockouts and search in the created
text files for the user in question.

http://www.microsoft.com/downloads/details.aspx?FamilyID=7AF2E69C-91F3-4E63-8629-B999ADDE0B9E&displaylang=en


You can also set the debug flag on NetLogon to track authentication. "This
creates a text file on the PDC that can be examined to determine which
clients are generating the bad password attempts."
http://support.microsoft.com/kb/189541
http://support.microsoft.com/kb/109626

--
Paul Bergson
MVP - Directory Services
MCT, MCSE, MCSA, Security+, BS CSci
2003, 2000 (Early Achiever), NT

http://www.pbbergs.com

Please no e-mails, any questions should be posted in the NewsGroup
This posting is provided "AS IS" with no warranties, and confers no rights.

"gbug" <gbug@xxxxxxxxxxxxxxxxxxxxxxxxx> wrote in message
news:22F20B77-7859-4A9F-B9D5-F2C7E007C4DC@xxxxxxxxxxxxxxxx
Hi all, i am having many problems with my AD. Continuously throughout the
day
i receive event stating: "Active Directory could not update the following
object with changes received from the domain controller at the following
network address because Active Directory was busy processing
information.",
and this one as well "The SAM database was unable to lockout the account
of
'username' due to a resource error, such as a hard disk write failure (the
specific error code is in the error data) . Accounts are locked after a
certain number of bad passwords are provided so please consider resetting
the
password of the account mentioned above."

Both events have to do with the same account - our main administrator
account. I want to find out where this account is logged onto, and where
logon requests are coming from. I am trying to figure out why these error
messages are occuring, and potentially remove this admin account from
running
any services, etc.




.



Relevant Pages

  • Re: disk mapping on web site
    ... Not sure what you means by "map the disk with the username". ... a particular account which is AFAIK error prone and in some cases difficult ... Keep in mind that mapped drives are tied to the account so you would need ... I need to move file from the server where there is my "web site" to ...
    (microsoft.public.dotnet.languages.vb)
  • Re: User Account Locked Out!!
    ... MVP - Directory Services ... A user could have mapped drives to a ... To help try and track down where the account is getting ... out use eventcombMT.exe from the Account Lockout tools found out ...
    (microsoft.public.windows.server.active_directory)
  • Re: How to display whole users sessions
    ... Usually what happens is a user has mapped drives to a resource from one ... To help try and track down where the account is getting locked out use ... sessions to find which users are connected to Active Directory. ...
    (microsoft.public.windows.server.active_directory)
  • Re: stream problems
    ... I use an ofstream to do this. ... Don't use mapped drives to access a file from a service. ... Even if a service runs under your account, it might not have the same drive mapping as you have. ... And make sure that your service only starts after all network services have been startet. ...
    (microsoft.public.vc.mfc)
  • Re: Recurring account lockouts
    ... A user could have mapped drives to a resource from one ... To help try and track down where the account is getting locked out use ... eventcomboMT.exe from the Account Lockout tools found out Microsoft's ... Use the built in search AccountLockouts and search in the created ...
    (microsoft.public.windows.server.active_directory)