kennysarmy Posted March 3, 2025 Posted March 3, 2025 I have a user who keeps getting locked out of AD. This is from the account lockout tool. If I reset the user account when they are logged in after a few minutes the count increases from zero until the user is unable to subsequently logon. I've captured a 4625 event but am unsure what this points to as being the cause. Any ideas? On all 3 PC's this user typically uses we've removed local profiles. I've also rebooted our two DC's. The user has also removed the Outlook app from their mobile device.
BKGarry Posted March 3, 2025 Posted March 3, 2025 (edited) Does the user have a RADIUS User authenticated WiFi profile on their phone? If the password isn't updated there, that may be causing it Edited March 3, 2025 by BKGarry typo correction
kennysarmy Posted March 3, 2025 Author Posted March 3, 2025 Does the user have a RADIUS User authenticated WiFi profile on their phone? If the password isn't updated there, that may be causing it Will investigate - cheers
Oaktech Posted March 3, 2025 Posted March 3, 2025 In my old AD envirnonment this was frequently caused by someone logging into a device, leaving it logged in, locking themselves out or changing their password on another device and the original device with an incorrect password trying to auth against resources like printers or drive shares. I know that's not what account lockout tool suggests, but sometimes it gets it wrong, particularly on drive shares. 2
mikes Posted March 11, 2025 Posted March 11, 2025 We had an issue with our Administrator account caused by DHCP trying to update DNS every hour with the wrong password, but I doubt this would affect any other user unless DHCP had been set up very strange!
Davit2005 Posted March 11, 2025 Posted March 11, 2025 (edited) There is a way using a sysinternal tool (cannot remember off top of my head the name of it). First find out what DC they are getting locked out on then search the logs for the IP. UPDATE: Oh yeah saw the OP tried this. Does the computer name not tie in with anything you recognise? Typical causes are password changed but a device still connecting using the old credential (i.e. mobile device, desktop). At a previous employment we stopped using lock on PCs and forced all desktops to restart nightly which solved a lot of this for us. People would leave them selves logged in to a PC, lock it and walk off then change their password. If you use Office 365 or Google maybe check logs for the user account to make sure someone is not trying to access their account. Edited March 11, 2025 by Davit2005
Oaktech Posted March 11, 2025 Posted March 11, 2025 I had weird results with that tool and got a better answer out of the Netwrix one - which is free and they aren't too spammy... https://www.netwrix.com/account_lockout_examiner.html 1
kennysarmy Posted March 12, 2025 Author Posted March 12, 2025 The issue was identified as a student device that a few weeks before the teacher had logged on to to setup a hotspot so they could use a payment machine for Young Enterprise!!!! I've explained to him the error of his ways. Sigh. 2
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now