Re: Urgent: All AD users are locked out



Sounds like you may have a virus on your network or someone is trying to crack passwords...

Can you logon to any of your domain controllers? If so, check the security log for event ID 644, which is logged when an account is locked. Specifically, look at the value for Caller Machine Name, which should tell you where the account lockouts are originating from.

If you cannot logon to any of your DCs, then try rebooting in DSRM and accessing the event log for the above information.

--

JPolicelli, MVP - Directory Services

http://www.policelli.com
http://policelli.com/blog

This posting is provided AS IS with no warranties and confers no rights. Always plan and test.

----

"Mhd" <Mhd@xxxxxxxxxxxxxxxxxxxxxxxxx> wrote in message news:07B0EF7C-EA9E-45AB-A236-1B3E450BD205@xxxxxxxxxxxxxxxx
Dears;

we have an w2k3 domain environment, with more than 300 users account.

Today morning all users are locked out frequently.

Please help to sort out this critical problem

thx

.



Relevant Pages

  • Re: Please help refresh my memory on AD DC
    ... When I boot my Laptop I reach the Logon screeen for XP Laptop and here ... admin account to be able to Login so I can control it from the DC. ... A domain user can by default logon to any domain computer, except Domain controllers. ... A Server has websites already hosted on it in a Workgroup and now I ...
    (microsoft.public.windows.server.active_directory)
  • Re: Domain Admins Account.... Locked Out ever 15 minutes
    ... You probably have an account on a machine that has an old password in it. ... Run LockoutStatus.exe from the link below and select the security template. ... > We have two Domain Controllers at headquarter, and two Domain Controllers, ... > Logon Failure: ...
    (microsoft.public.windows.server.active_directory)
  • Two Differnet ADU&C lists
    ... I have two domain controllers in my domain. ... The listings in the DB are the same, ... account is configured one way one the first DC and is ... configured to logon to any computer in the domain at any ...
    (microsoft.public.windows.server.active_directory)
  • Possible Bad Question
    ... Group Policy MMC snap-in on JennyW2KP and configure the account lockout ... lockout Jennifer's Domain Account after two bad logon attempts. ... 2000 Network because the Local Group Policy and Default Domain Controllers ...
    (microsoft.public.cert.exam.mcsa)
  • Possible Bad Question
    ... Group Policy MMC snap-in on JennyW2KP and configure the account lockout ... lockout Jennifer's Domain Account after two bad logon attempts. ... 2000 Network because the Local Group Policy and Default Domain Controllers ...
    (microsoft.public.cert.exam.mcse)

Loading