How to find what process is causing account lockout?

  • Thread starter Thread starter WorkingStiff
  • Start date Start date
W

WorkingStiff

I set up account lockout policies to lock an account after several tries, but when I
changed my password, the account gets locked out constantly (though just retrying a few
times usually gets me in). I've turned on as many security logging options as I can find,
but no logs show what process is causing the lockout. This lockout occurs even if I
disconnect the machine from the network, so it must be a process on the local machine.

How can I find what process is causing the lockout?

Thanks
RDPfan
 
what is the account lockout threshold? If it is too low it will lock out as
soon as the password is blown once
 
Threshhold is actually high (about 20). I went through each service and found the ones
that were NT AUTHORITY/LocalService which had a password and changed them to the local
system acct and haven't had the problem since. I don't really understand what I did
exactly, but nothing has broken as far as I can tell so I guess this problem is solved.
thanks!
 
Back
Top