Jump to content

Recommended Posts

Posted

I have a user who keeps getting locked out of AD.

 

This is from the account lockout tool.

 

1.JPG

 

If I reset the user account when they are logged in after a few minutes the count increases from zero until the user is unable to subsequently logon.

 

I've captured a 4625 event but am unsure what this points to as being the cause.

 

2.JPG

 

 

Any ideas?

 

On all 3 PC's this user typically uses we've removed local profiles.

 

I've also rebooted our two DC's.

 

The user has also removed the Outlook app from their mobile device.

Posted (edited)
Does the user have a RADIUS User authenticated WiFi profile on their phone? If the password isn't updated there, that may be causing it Edited by BKGarry
typo correction
Posted
Does the user have a RADIUS User authenticated WiFi profile on their phone? If the password isn't updated there, that may be causing it

 

Will investigate - cheers

Posted
In my old AD envirnonment this was frequently caused by someone logging into a device, leaving it logged in, locking themselves out or changing their password on another device and the original device with an incorrect password trying to auth against resources like printers or drive shares. I know that's not what account lockout tool suggests, but sometimes it gets it wrong, particularly on drive shares.
  • Thanks 2
Posted
We had an issue with our Administrator account caused by DHCP trying to update DNS every hour with the wrong password, but I doubt this would affect any other user unless DHCP had been set up very strange!
Posted (edited)

There is a way using a sysinternal tool (cannot remember off top of my head the name of it). First find out what DC they are getting locked out on then search the logs for the IP.

 

UPDATE: Oh yeah saw the OP tried this. Does the computer name not tie in with anything you recognise?

 

Typical causes are password changed but a device still connecting using the old credential (i.e. mobile device, desktop). At a previous employment we stopped using lock on PCs and forced all desktops to restart nightly which solved a lot of this for us. People would leave them selves logged in to a PC, lock it and walk off then change their password.

 

If you use Office 365 or Google maybe check logs for the user account to make sure someone is not trying to access their account.

Edited by Davit2005
Posted

The issue was identified as a student device that a few weeks before the teacher had logged on to to setup a hotspot so they could use a payment machine for Young Enterprise!!!!

 

I've explained to him the error of his ways. Sigh.

  • Thanks 2

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...