Account Lock Outs

  • Thread starter Thread starter kef
  • Start date Start date
K

kef

Summary: Account lock outs are occuring and currently
there are NO GPs or any account policy set to lock out
accounts.

Some Detail: The lock outs vary between users, time, and
location (i.e. internal and remote)and also if they are
logged onto the domain or locally. Sometimes the lock
outs affect a few people and other times it affects the
majority.

The infrastructure in Win 2000 server with most recent
patches and 2000/XP clients. All server are at the same
location and in the same domain.

There is a Windows 2003 Terminal Server (the schema has
not been extended nor is this a domain controller)

A Radius server is installed.

External DNS is Linux -- internal is Win2000 AD

I have research this at MS but nothing really seems to
fit.

Any help would be great.
 
For domain accounts, account lockout can only be configured at the domain
policy level. I know you said it is not configured, but double check that at
the domain level it is defined as zero for the account lockout threshold and
the same for any Local Security Policy or at the OU level of machines that
are being affected for local account lock outs. It may also help to enable
auditing of logon events on the domain controller and machines being
affected to see what is being recorded in the security log in Event Viewer.
Running the "net accounts" command may also help in viewing the applied
lockout policy. --- Steve

http://is-it-true.org/nt/atips/atips155.shtml
 
Back
Top