account locked out multiple times per day



I'm having a bizarre problem with an account that gets locked out
multiple times per day.

My account was previously a member of the domain admins group for a
long time. Bad, I know. So, recently I pulled the account from domain
admins and made it a member of domain users.

However, it seems like if I'm not a member of domain admins, my
account gets locked out every hour or two. From the SBS 2003 security
logs:

Event Type: Failure Audit
Event Source: Security
Event Category: Logon/Logoff
Event ID: 539
Date: 7/18/2007
Time: 3:50:42 PM
User: NT AUTHORITY\SYSTEM
Computer: BIGSERVER01
Description:
Logon Failure:
Reason: Account locked out
User Name: jobrien
Domain: SERVER01
Logon Type: 3
Logon Process: NtLmSsp
Authentication Package: NTLM
Workstation Name: 606
Caller User Name: -
Caller Domain: -
Caller Logon ID: -
Caller Process ID: -
Transited Services: -
Source Network Address: 192.168.1.138
Source Port: 2193

Prior to this entry are multiple success audits from my account and
others, which seems normal.

I have checked my machine and others for scheduled processes that
might be running with my username, etc., but I don't see anything
unusual. The security policy is set to lock out accounts after 50
invalid login attempts. I assume that those invalid attempts should
show up in the security log, which they do not.

Can anyone give me advice on how to troubleshoot this?

Thanks.
Joseph

.



Relevant Pages

  • Re: "Edit Users..." Menu Item Disabled in Telephony Management Sna
    ... To make it clear i used account that is member of domain admins and group ... I set up also the account (already member of domain admins and trough this ... Running "tapicfg show" revealed that I had no Active Directory TAPI ...
    (microsoft.public.win32.programmer.tapi)
  • Re: Incoming E-Mail - cant create contact in OU
    ... Go to the OU in security/advanced I added my sharepoint application pool ... that account a little (if the web app is compromised or something, ... Now I understand that you have given the account "full rights" of the OU, ... So I started with giving the app pool account domain admins permissions then ...
    (microsoft.public.sharepoint.windowsservices)
  • Re: Administrator account / Domian Addmin rights
    ... There is no difference between one Domain Admins member ... sharing an empowered account between people, ... The best thing however is to not provide Domain Admins membership, ... Finally - every administrator should know that changing the password ...
    (microsoft.public.win2000.security)
  • Re: Password Problem with Server Login
    ... We periodically reboot our server and had ... login with the Administrator account like we usually do and the ... We also tried an account ... however we have other users who are members of the "Domain Admins". ...
    (microsoft.public.windows.server.active_directory)
  • Re: Permission for user account in AD
    ... This is the behavior when a user is member of one or more protected groups ... > Has noticed that I can not change permission for user ... > account (in AD User&Computers right-click account, ... > For user account that never was member of Domain Admins ...
    (microsoft.public.win2000.active_directory)