T
Troy
How do make a domain user in AD locked out after say 3
failed attempts with a bad password?
failed attempts with a bad password?
You have to do it through Group Policy.
In Win2k this is what you can do. (maybe works on win2003 also)
If you know how to get to domain policies skip these steps
Open up AD Users and Computers.
Right click on either the Domain or the OU and select Properties. (Domain
will set the policy for all users)
Click on Domain Policy Tab
Click on Edit
In Group Policy Edit window
Drill down to Computer Configuration->Windows Settings->Security
Settings->Account Policies->Account Lockout Policy
After you set the settings and close out of the Policy MMC, refresh your
policy by typing
secedit /refreshpolicy machine_policy /enforce