M
Mark
One particular user account keeps getting locked out, the
following event is logged several times before the account
is finally locked.
Event Type: Failure Audit
Event Source: Security
Event Category: Logon/Logoff
Event ID: 529
Date: 09/07/2003
Time: 09:05:56
User: NT AUTHORITY\SYSTEM
Computer: <>
Description:
Logon Failure:
Reason: Unknown user name or bad password
User Name: <>
Domain: <>
Logon Type: 3
Logon Process: NtLmSsp
Authentication Package: NTLM
Workstation Name: <>
This occurs sometimes while the user is already logged
on. It is not a manually entered username or password
error.
This problem seems to have started since the password was
changed, which leads me to believe there may, somewhere,
be a service using this particular account with the old
password. If so any ideas how I go about finding the
suspected service?
Thanks in Advance
Mark
following event is logged several times before the account
is finally locked.
Event Type: Failure Audit
Event Source: Security
Event Category: Logon/Logoff
Event ID: 529
Date: 09/07/2003
Time: 09:05:56
User: NT AUTHORITY\SYSTEM
Computer: <>
Description:
Logon Failure:
Reason: Unknown user name or bad password
User Name: <>
Domain: <>
Logon Type: 3
Logon Process: NtLmSsp
Authentication Package: NTLM
Workstation Name: <>
This occurs sometimes while the user is already logged
on. It is not a manually entered username or password
error.
This problem seems to have started since the password was
changed, which leads me to believe there may, somewhere,
be a service using this particular account with the old
password. If so any ideas how I go about finding the
suspected service?
Thanks in Advance
Mark