Re: Ad2003 - locked-out accounts are not unlocking automatically



Why is the check greyed? Are you not an admin?
What is the scope of the problem exactly? Is it everyone gets the same
results or just a few users?
What do you see in the event logs of the domain controllers (seems like
something you should have checked by now, but want to be sure we're covering
the bases)?
What I think you want to look for the most is that the policy is being
applied to the domain controllers as expected and without issue.




"Radovan Vojtek" <RadovanVojtek@xxxxxxxxxxxxxxxxxxxxxxxxx> wrote in message
news:F458C02E-42C4-4785-BD61-D8B9308B5E03@xxxxxxxxxxxxxxxx
Hi all,

I've set my domain as follows:

Account lockout duration: 60 minutes
Account lockout threshold: 10 invalid logon attempts
Reset account lockout counter after: 60 minutes

However, accounts that got locked-out are not automatically unlocked after
60min. In ADUC the checkob for unlock user is greyed but I can list tha
account with the following LDAP query:

(&(&(&(&(objectCategory=person)(objectClass=user)(lockoutTime:1.2.840.113556.1.4.804:=4294967295)))))

The only way to unlock that account is user the VBS script with this
command:

objUser.IsAccountLocked = FALSE


Is there any way to find out what's wrong with the domain?

Thanks,
--
R.V.


.



Relevant Pages

  • Re: Automatically user lockout - big problem
    ... Check the security logs of the domain controllers to ... By default logging of account ... Comb can be used to scan domain computers for that account lockout event. ...
    (microsoft.public.windows.server.security)
  • RE: Finding Domain Service Running Every 12 Hours
    ... we can enable the Audit Policy settings in the ... Default Domain policy on the domain level to record the account logon ... When the account lockout occurs, we can retrieve both the Security ... To determine the domain controllers that are involved with the lockout, ...
    (microsoft.public.windows.server.general)
  • Re: NT User A/C Lock
    ... credentials in network shares, XP stored credentials. ... controllers will show account lockout events and the domain computers will ... record a logon failure due to an account lockout. ... Event Comb to search your computers and domain controllers for specific ...
    (microsoft.public.security)
  • Re: Account lockout duration=30 minutes, however account remains locked indefinitely.
    ... Try running net accounts on the domain controllers to see what they report ... as the account lockout setting. ... Security Policy. ...
    (microsoft.public.win2000.security)
  • Account Unlock event not written to the eventlog
    ... Audit Account Logon Events ... Account Lockout Policy is set to the following: ... If the Account lockout duration rule fires to unlock an account, ...
    (microsoft.public.win2000.security)