Active Directory randomly locks out users

  • Thread starter Thread starter Rob Richards
  • Start date Start date
R

Rob Richards

Hey There,

Our company has two Win2K Server DC's( A primary (SP3) and a secondary
(SP4)), and for some reason the users keep getting locked out. The
secondary DC is used for a mail server and has Exchange 5.5 SP4 Its
not the same users either its random. All my services on the main DC
are using the LocalSystem account, the users dont have access to
install programs so i can rule out services being the problem. I
checked out the users in LDP for duplicate entries and there were no
duplicates in there. I also put all the users into another OU i
created and ran repadmin /syncall but still (although less frequently)
the users are locking out. Ive also ran netdiag /v, dcdiag /v and all
the tests passed accept for the kccevent which passed 15 minutes or so
later. The only thing i can think of is that drives are mapped to the
user's login script, but we've had drive mapping in our scripts for
over a year now without user's being locked out.

If anyone has any more suggestions i would much appreciate it

Cheers
Rob
 
How is your account lockout policy setup? Have you enabled account logon
event auditing on your domain controllers and looked in the security log for
more logon details? There is a white paper that includes sections on
troubleshooting account lockouts here:

http://www.microsoft.com/downloads/...90-a13b-4977-a4fc-3e2b67e3748e&DisplayLang=en

Also here is a support article you may want to look at:

http://support.microsoft.com/default.aspx?scid=kb;en-us;264678


------------------------------------------------------------------
Mike Aubert
MCSE, MCSD, MCDBA
(e-mail address removed)

Note the "news2" in my email address is temporary and may be changed in the
future, remove it to email me at my Permanente address.
This posting is provided "AS IS" with no warranties, and confers no rights.
 
Back
Top