Domain User Account Getting Locked Frequently
In this case the computer name is lon dc01.
Domain user account getting locked frequently. This just started last week. We have 144kbps idsl internet access out at the remote location. The name of the computer from which the lock was made is specified in the caller computer name value. Use below tools to find out the source of the account lockout on the server.
Find the domain controller with the pdc emulator role. Enable success and failure for the audit user account management policy. Cause account getting locked due to typing wrong password more than the limit set by your organisation saved old password resolution first check keyboard is set to correct language and make. Auditing is now turned on and event 4740 will be logged in the security events logs when an account is locked out.
One on my users is being locked out of his active directory account on a daily basis. If you have a single domain controller shame on you then you can skip to the next step. You will see a list of events of locking domain user accounts on this dc with an event message a user account was locked out find the last entry in the log containing the name of the desired user in the account name value. However the user is not failing any attempts when he unlocks his system.
If you found the account is getting locked from a mobile device and unable to fix the by performing above steps take the necessary backup and wipe the device completely and reconfigure the device. For the most part accounts in the remote site do not become locked out we have 2 dcs in the home site one at the remote site. We run a vpn using sonicwall firewalls between locations with a single domain the domain is in mixed mode no nt bdcs some windows 9x machines. This occurs between 10 and 18 hours after each reset.
Account lockout and management tool. I can see that the reason for the lockout is a failed number of password attempts. Check the event security log for event id 4740 a user account was locked out it will tell you the bad computer name on that the particular account is locking out.