jmak Posted March 10, 2016 Posted March 10, 2016 I changed my AD password on Monday and since then it keeps locking me out. Obviously I can't guarantee that I never type it incorrectly, but I'm definitely only getting
Sagima Posted March 10, 2016 Posted March 10, 2016 We used to find mobile devices forced lockouts - check you've changed your wifi/email passswords on your phone/tablets 1
bald_pig Posted March 10, 2016 Posted March 10, 2016 Any services or tasks that run with your credentials? Check your ADC's security log to see where the authentication requests are coming from. 1
jmak Posted March 10, 2016 Author Posted March 10, 2016 I changed my AD password on Monday and since then it keeps locking me out. Obviously I can't guarantee that I never type it incorrectly, but I'm definitely only getting You guys are good - I pressed submit before I'd finished. So: definitely only getting one chance at most. I was locked out at the end of yesterday afternoon, so closed down and went home. I thought it might be unlocked this morning, but it wasn't. I reset on the DC and logged in successfully. Had to leave my desk, came back 5 minutes later and it was locked out. Message is: the referenced account is currently locked out and may not be logged on to. DC is server 2012r2. I'm not aware of having turned AD logging on - will there be anything available as default and if not, where do I turn it on? I can't think of anything using my account, but was guessing that was most likely - just not sure where to start looking... Thanks [emoji17]
jmak Posted March 10, 2016 Author Posted March 10, 2016 We used to find mobile devices forced lockouts - check you've changed your wifi/email passswords on your phone/tablets Email is the only app using work credentials on my phone and that's on the County domain and not giving problems....
bald_pig Posted March 10, 2016 Posted March 10, 2016 Windows security auditing runs on all machines as far as I'm aware, you'll be looking at the "audit failure" entries. 1
jmak Posted March 10, 2016 Author Posted March 10, 2016 I think I haven't given full information in my earlier posts. Having been through the security events in the log, there are no logon failures for my account. I can see my machine log on and the admin account that I used to unlock my account logon and then logoff and then my normal account logon successfully. Of course I didn't actually logoff - I just locked my machine, but then couldn't unlock it again. I can't see any other events relating to my account until my next successful logon - after the next cycle of logging on with the admin account. There only unusual thing I can see is that there seem to be dozens of events associated with my logon - all successful - which appear to relate to the privileges I have and various Kerberos events. Could the lock out be due to the volume of logons in a short period of time? Sorry for long post relating to something so trivial. Thanks
bald_pig Posted March 10, 2016 Posted March 10, 2016 To be clear, you are seeing this on the DC and not your local machine? you might need to grab the lockout tools from the MS website to help track down the lockouts. 1
jmak Posted March 10, 2016 Author Posted March 10, 2016 To be clear, you are seeing this on the DC and not your local machine? you might need to grab the lockout tools from the MS website to help track down the lockouts. I'm looking at the logs on the DC. I'm trying to logon to/unlock my local machine.
Joanne Posted March 10, 2016 Posted March 10, 2016 If it's Windows 8-10 is your account linked to a Microsoft account? could it be anything to do with that? 1
FN-GM Posted March 10, 2016 Posted March 10, 2016 One of the following is the likely cause Mobile connecting to email with wrong password Device connecting to radius with wrong password Left yourself logged onto a server Service using your account with wrong password. 1
jmak Posted March 10, 2016 Author Posted March 10, 2016 One of the following is the likely cause Mobile connecting to email with wrong password Device connecting to radius with wrong password Left yourself logged onto a server Service using your account with wrong password. The only account I have on my mobile is my email and that's on an external County domain and the domain I'm locked out of is a. Local domain We don't have radius set up (yet) I did leave myself signed in on a couple of servers after I'd changed my password, but signed out and then in again on all servers on Tuesday as it struck me that might be the problem. Is it worth rebooting servers given that I've definitely signed out since changing passwords? Services: any idea how I could track down what it might be, since I'm not seeing any logon failures? If it's Windows 8-10 is your account linked to a Microsoft account? could it be anything to do with that? It is on a windows 8 machine, but I've never linked it to a Microsoft account. My Microsoft account is on another different domain
john Posted March 11, 2016 Posted March 11, 2016 Have you installed something that is using your credentials as a service that could be a good spot for it to be caught.
jmak Posted March 11, 2016 Author Posted March 11, 2016 Have you installed something that is using your credentials as a service that could be a good spot for it to be caught. Almost certainly, but I can't think what! I'm starting to think something from my PC or profile, as it was unlocked this morning. Not sure what might only run when I'm logged in to my PC. Current plan is to shut down my PC at the end of the day and reset password/unlock account from a different machine, then work from a different machine on Monday. If that sorts it, I'll rebuild my machine - I need to update to win 10 to get RSAT for the win 10 clients I'm about to add to the domain. Any hints on where I'll find logs to investigate properly?
john Posted March 14, 2016 Posted March 14, 2016 If its something service related on your machine look in Services in the Logon as column if you see anything with your username go in to that service and fix it 1
Areku Posted March 14, 2016 Posted March 14, 2016 been a while since ive ran into this but this is what i used to do: use lockoutstatus to identify which DC that locked it. (and time) check the security log on that DC for the eventlog showing it being locked. then as part of the details of that event log it will show you the "client" hostname where the account was attempted to be used. should tell you what machine/server to start looking at. 1
ADMaster Posted March 14, 2016 Posted March 14, 2016 Do you see any log on failures at all? I thought the default was to audit only success, but technet indicates no auditing as default. Edit the default domain controller policy and go to; computer configuration > Windows security > Security settings > Local policies> audit policy Change the audit account log on events to success and failure. here is the tech net entry https://technet.microsoft.com/en-us/library/cc976367.aspx 1
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now