Multiple accounts getting locked out.


hi,

we running active directory 2008 r2 in mixed domain because still have 1 2003 dc.
several of our ad accounts locked out, mine gets locked out 2-3 times day.
i've used altools , dc's security logs have traced down laptop. i've checked usuals on laptop, network drives, scheduled tasks, services, scripts etc. please dont suggest obvious.
ive enabled kerberos client logging on pc system event logs dont tell me much, these:

a kerberos error message received:

on logon session

client time:

server time: 5:14:18.0000 7/16/2013 z

error code: 0xe kdc_err_etype_notsupp

i've followed article enable netlogon logs on domain controller.

http://msviennatechnoblog.wordpress.com/2011/12/05/ad-enable-netlogon-debug-logging/

in netlogon logs, these entries same time acct gets locked out

07/16 14:12:50 [logon] domain: samlogon: transitive network logon of domain\user from mylaptop (via domain controller) entered
07/16 14:12:50 [logon] domain: samlogon: transitive network logon of domain\user mylaptop (via domain controller) returns 0xc000006a

i've tried usiing netmon , process explorer see process on laptop trying authenticate bit hard trace.

does have experience in tracing kind of issue.

for other users affected have traced down desktop/laptops im looking trying when gets locked out.

something wierd our dba had issue today , password hasnt change in 4 years!!! , said wasnt trying authenticate when happened , believe him.

i know in windows xp there used tool called alockout.dll dont think works win7. know if tool works win7 64bit?

any or suggestions appreciated.

 i've checked usuals on laptop, network drives, scheduled tasks, services, scripts etc. please dont suggest obvious.

please list down "all" obvious things had tried ? community members suggest else or suggest new things.

regards, santosh | mvp

i not represent organisation work for, opinions expressed here, own.

posting provided as is no warranties or guarantees , confers no rights.

blog | wiki



Windows Server  >  Windows Server General Forum



Comments

Popular posts from this blog

some help on Event 540

WMI Repository 4GB limit - Win 2003 Ent Question

Event ID 1302 (error 1307) DFS replication service encountered an error while writing to the debug log file