E
Ernst Meyer
I am experiencing problem with domain account lockouts for no apparent reason. I receive Event IDs 642 and 644 on either of my two domain controllers. After re-enabling the account, the account will lockout once again. I checked that I am not running any services with my user id.
All of this started when passwords were changed. A few hours ago I changed the passwords for one of the account back to its old password. Initially this appeared to have done the trick, but now I receive lockout messages again.
I have copied the syntax of the lockout into the body of this message. I would appreciate any feedback, as I am close to pulling my hair out. Thanks.
--------------
Event ID: 644
Operating System : Windows 2000 Domain Controller
Event Origin Details:
S.E.L.M. Event ID: 1063085903_000000000000982
Date & Time: 9/09/2003 - 3:09:00 PM
Within N.O.Time: Yes
Source: Security
Computer: IR-FILE-SRV
User: NT AUTHORITY\SYSTEM
User Account Locked Out:
Target Account Name: username
Target Account ID: IR\username
Caller Machine Name: IR-EXCH-SRV
Caller User Name: IR-FILE-SRV$
Caller Domain: IR
Caller Logon ID: (0x0,0x3E7)
Extended Details:
User SID: S-1-5-18
-----------------------------------------
Event ID: 642
Operating System : Windows 2000 Domain Controller
Event Origin Details:
S.E.L.M. Event ID: 1063085903_000000000000984
Date & Time: 9/09/2003 - 3:09:00 PM
Within N.O.Time: Yes
Source: Security
Computer: IR-FILE-SRV
User: NT AUTHORITY\SYSTEM
User Account Changed:
Account Locked.
Target Account Name: username
Target Domain: IR
Target Account ID: IR\username
Caller User Name: IR-FILE-SRV$
Caller Domain: IR
Caller Logon ID: (0x0,0x3E7)
Privileges: -
Extended Details:
User SID: S-1-5-18
All of this started when passwords were changed. A few hours ago I changed the passwords for one of the account back to its old password. Initially this appeared to have done the trick, but now I receive lockout messages again.
I have copied the syntax of the lockout into the body of this message. I would appreciate any feedback, as I am close to pulling my hair out. Thanks.
--------------
Event ID: 644
Operating System : Windows 2000 Domain Controller
Event Origin Details:
S.E.L.M. Event ID: 1063085903_000000000000982
Date & Time: 9/09/2003 - 3:09:00 PM
Within N.O.Time: Yes
Source: Security
Computer: IR-FILE-SRV
User: NT AUTHORITY\SYSTEM
User Account Locked Out:
Target Account Name: username
Target Account ID: IR\username
Caller Machine Name: IR-EXCH-SRV
Caller User Name: IR-FILE-SRV$
Caller Domain: IR
Caller Logon ID: (0x0,0x3E7)
Extended Details:
User SID: S-1-5-18
-----------------------------------------
Event ID: 642
Operating System : Windows 2000 Domain Controller
Event Origin Details:
S.E.L.M. Event ID: 1063085903_000000000000984
Date & Time: 9/09/2003 - 3:09:00 PM
Within N.O.Time: Yes
Source: Security
Computer: IR-FILE-SRV
User: NT AUTHORITY\SYSTEM
User Account Changed:
Account Locked.
Target Account Name: username
Target Domain: IR
Target Account ID: IR\username
Caller User Name: IR-FILE-SRV$
Caller Domain: IR
Caller Logon ID: (0x0,0x3E7)
Privileges: -
Extended Details:
User SID: S-1-5-18