Random Account Lockout

From: Hot Gal (briteeyez_at_hotmail.com)
Date: 05/11/04


Date: Tue, 11 May 2004 12:17:11 -0400

Hi

User accounts in active directory are randomly locked out. I would like to
find a solution.

Security Logs on domain controlers show...

Event Type: Failure Audit
Event Source: Security
Event Category: Account Logon
Event ID: 537
Date: 11/05/2004
Time: 10:32:19 a.m.
User: NT AUTHORITY\SYSTEM
Computer: SERVER
Description: An error occurred during logon

and

Event Type: Failure Audit
Event Source: Security
Event Category: Account Logon
Event ID: 681
Date: 11/05/2004
Time: 10:32:19 a.m.
User: NT AUTHORITY\SYSTEM
Computer: SERVER
Description:
The logon to account: USEREXAMPLE
 by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0
 from workstation: \\WORKSTATIONEXAMPLE
 failed. The error code was: 3221226036

and...

Event Type: Failure Audit
Event Source: Security
Event Category: Logon/Logoff
Event ID: 539
Date: 11/05/2004
Time: 10:32:19a.m.
User: NT AUTHORITY\SYSTEM
Computer: FS06
Description:
Logon Failure:
      Reason: Account locked out
      User Name: USEREXAMPLE
      Domain: SKYNZ
      Logon Type: 3
      Logon Process: NtLmSsp
      Authentication Package: NTLM
      Workstation Name: \\WORKSTATIONEXAMPLE

Debug logging for the Net logon services shows...

1. Our company runs all versions of Microsoft Windows. 200 and XP
Workstation, 2000 and 2003 Server.

2. Our Domain Controlers are all 2000 Server with service pack4.

3. Our domain policy is set such that 3 bad attempts locks an account out.

Can anyone please help me. What can I do to solve this problem?



Relevant Pages

  • [EC-SA-01.2003] Windows XP "welcome screen" exposes the names of all the members of the l
    ... logon screen with what is called "Welcome Screen". ... (including the original administrator account, ... Using the "welcome screen" actually disables / ignores the security ...
    (Bugtraq)
  • Re: ATTN : Microsoft - Security Event 529....Second Request for help....
    ... According to the events, the logon ... failure is from the local machine account. ... disconnected from the network. ... Security Event ID 529 is a failure audit for logon/logoff. ...
    (microsoft.public.windows.server.sbs)
  • RE: Event ID 529 on cleint workstation
    ... Security Event ID 529 is a failure audit for logon/logoff. ... "logon events" generate the events on domain controllers for domain account ... The Event 529 was caused by the machine account password not being ... I suggest that you re-join the client to ...
    (microsoft.public.windows.server.sbs)
  • Re: Is it really true that NTFS is secure?
    ... The account Group got put back in the Administrator group again. ... Event Source: Security ... The logon to account: Administrator ...
    (microsoft.public.security)
  • change administrator password
    ... the Security Event Viewer. ... Is there a procedure to follow when changing the administrator password, ... Event Type: Failure Audit ... Logon Failure: ...
    (microsoft.public.win2000.security)