AD accout locked out when name matches workstation account

Tech Tip: Click here to run a free scan for Windows Errors and optimize PC performance



I have observed a problem here on our XP/2003 environment. When I login to a
local Worstation account on any of our XP boxes a failed login attempt is
recorded in the AD server event log.

The entry in the AD event log clearly states that the domain of the
attempted login is the worstation name but if the username happens to match
the username of a domain account then that account will get locked out.

There seem to be two separate mis-features (bugs) here. Firstly I can't see
why domain member workstations are sending authentication requests to the
domain controller for local account logins. Secondly the domain controller is
failing to notice that these authetication requests are if fact not for the
domain.

This is, needless to say, very annoying.

I've seen a number of threads here with people having problems that could be
caused by these mis-features but none that I've found actually mention the
issue of the domain controller apparently getting confused as to which domain
an authentication request relates to.
.



Relevant Pages

  • Weakness introduced by denying remote logins on AIX, possibly others
    ... AIX 4.3.3 and AIX 5.1, ... is possible to remotely enumerate the passwords of a known AIX account. ... believed to be in the response from the login program after authentication ... Give accounts that have been restricted from remote logins strong passwords. ...
    (Security-Basics)
  • Re: AD accout locked out when name matches workstation account
    ... login to a local Worstation account on any of our XP boxes a failed ... login attempt is recorded in the AD server event log. ... requests to the domain controller for local account logins. ...
    (microsoft.public.windows.server.active_directory)
  • Re: Please! Doesnt anyone know a better way to do this?
    ... account, they need to automatically be directed to the page to enter data ... session variable on the Account page. ... I assume here that you're checking a database when the user attempts to ... When a new user attempts to login or clicks to register, ...
    (microsoft.public.dotnet.framework.aspnet)
  • WinXP laptop, simple-style login conn to Win2000 share, error
    ... So, to simplify matters, add all machines to the domain. ... local machine accounts) to keep track of... ... the local account information. ... the "pushbutton login") and configure the Laptops to auto ...
    (microsoft.public.windowsxp.security_admin)
  • [Full-disclosure] Dexia website security alert
    ... A few days ago I sent a mail to the Dexia bank about ... one is for the online banking account and one ... The problem with the "members' login" was that ... encryption and b) if you enter a bad username or password both ...
    (Full-Disclosure)