Jump to content

Recommended Posts

Posted (edited)

We have a particular user in our organisation that will frequently call in the morning, saying that their account is inaccessible.

This can be fixed by disabling and re-enabling the account, but I do not know what is causing this.

 

When this occurs, there is not a recent bad password attempt shown within AD attribute editor nor within Azure.

The account does not display as being disabled through our AD either.

 

I am at a loss for where to look next.

Edited by MEvansLA
Posted
Do you use AD/Radius for your wireless? That's normally what does it for us (iPhones are particularly bad for just hammering away with the wrong creds)
  • Thanks 1
Posted (edited)

Enable logon audits on the DCs and use lockoutstatus tool https://www.microsoft.com/en-gb/download/details.aspx?id=15201

 

Using the tool will tell you which domain controller the user is getting locked out on then search the security logs for the user. This will most of the time give you an IP address where the account is getting locked out from.

 

We used this a lot at my previous place. Do you have MFA on the account where possible???

 

Mostly this was caused by a mobile device logged into outlook with old password after user had changed password.

Edited by Davit2005
  • Thanks 1
Posted
Check the Radius logs - on the server that manages your Radius, look in the security logs for event ID 6273 - these will tell you any failed attempts at accessing Radius
Posted
I will definitely look into this further. We only have one user who frequents with this issue, but we have had a few here and there with the same or similar issue.

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...