MEvansLA Posted October 6, 2022 Posted October 6, 2022 (edited) We have a particular user in our organisation that will frequently call in the morning, saying that their account is inaccessible. This can be fixed by disabling and re-enabling the account, but I do not know what is causing this. When this occurs, there is not a recent bad password attempt shown within AD attribute editor nor within Azure. The account does not display as being disabled through our AD either. I am at a loss for where to look next. Edited October 6, 2022 by MEvansLA
Rob_D Posted October 6, 2022 Posted October 6, 2022 Do you use AD/Radius for your wireless? That's normally what does it for us (iPhones are particularly bad for just hammering away with the wrong creds) 1
MEvansLA Posted October 6, 2022 Author Posted October 6, 2022 Yes, we are. I will sign them out of all devices and have a new password set. Do you know of any other methods around this?
Rob_D Posted October 6, 2022 Posted October 6, 2022 Sorry, we just bug staff to check their mobile devices
Davit2005 Posted October 6, 2022 Posted October 6, 2022 (edited) Enable logon audits on the DCs and use lockoutstatus tool https://www.microsoft.com/en-gb/download/details.aspx?id=15201 Using the tool will tell you which domain controller the user is getting locked out on then search the security logs for the user. This will most of the time give you an IP address where the account is getting locked out from. We used this a lot at my previous place. Do you have MFA on the account where possible??? Mostly this was caused by a mobile device logged into outlook with old password after user had changed password. Edited October 6, 2022 by Davit2005 1
clareq Posted October 6, 2022 Posted October 6, 2022 Check the Radius logs - on the server that manages your Radius, look in the security logs for event ID 6273 - these will tell you any failed attempts at accessing Radius
Oaktech Posted October 6, 2022 Posted October 6, 2022 We've got one user who is a nightmare for this... She forgets her password every couple of days and leaves multiple machines logged in resulting in repeated lockouts, I'm using https://www.netwrix.com/account_lockout_examiner.html to track down the devices in question.
Davit2005 Posted October 6, 2022 Posted October 6, 2022 Yes we decided to shutdown desktop machines also for this as users used to leave themselves logged in but the machine locked.
MEvansLA Posted October 6, 2022 Author Posted October 6, 2022 I will definitely look into this further. We only have one user who frequents with this issue, but we have had a few here and there with the same or similar issue.
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now