Jump to content

Recommended Posts

Posted

Afternoon all!

Strange one I can't get my head around. We have one member of staff who's AD account is constantly being locked out. She isn't using an incorrect password anywhere, there's nothing nefarious like annoyed students spamming her username, and it only happens when she's logged on and in school.

Rebuilt the laptop entirely to rule out some dodgy cached credentials, despite only being built onto windows 11 a few weeks ago. Identical laptop to 80 others, identically setup user too. Password has also been reset.

Security log in event viewer always gives the same:

 

A user account was locked out.....

...

Additional Information:
    Caller Computer Name:    \\SMOOTHWALL

 

Said user is correctly filtered, and shows she's logged into smoothwall when browsing to a blocked site. I can't see anything untowards in the Smoothwall logs. Authentication is IDEX across the board (and Google for the chromebooks). 

 

I don't believe it's RADIUS related - that's computer account level for the wifi and she doesn't have any other connection to smoothwall other than her school laptop. Google & AD passwords are synced and the same.

I just can't see any patterns. Badpasswordtime in AD is always recent so clearly something is attempting to authenticate badly, but what?

Completely flummoxed! Any ideas of where else I can look?

 

Posted

There was an old NTLM trick we used to work around a bug in IE (yes, very old!) that used to cause this.

I'd have a look and ditch NTLM - Microsoft wants rid of it anyway!

Posted
11 hours ago, tom_newton said:

There was an old NTLM trick we used to work around a bug in IE (yes, very old!) that used to cause this.

I'd have a look and ditch NTLM - Microsoft wants rid of it anyway!

I think I stumbled across this in an ancient thread and discounted it as we're using IDEX for authentication - is this a setting in the Smoothwall itself?

Posted

Any chance they're logged in somewhere and the password has been changed since that login? I've seen that happen before.

 

Maybe check open connections on File Servers to see if this might be the case.

Posted
Just now, bknaggs said:

Any chance they're logged in somewhere and the password has been changed since that login? I've seen that happen before.

 

Maybe check open connections on File Servers to see if this might be the case.

Good shout cheers - just checked and all clear. Next to nothing on file server any more but anything's worth a look! :) It's the fact that it specifically flags Smoothwall which is flummoxing me. 

Posted
3 hours ago, synaesthesia said:

Good shout cheers - just checked and all clear. Next to nothing on file server any more but anything's worth a look! :) It's the fact that it specifically flags Smoothwall which is flummoxing me. 

Hardcoded proxy with saved creds on a device/application that needed proxy settings?

Posted
1 minute ago, PaddyNewman said:

Hardcoded proxy with saved creds on a device/application that needed proxy settings?

No, the machine is set up identically to every other staff device. Transparent proxy. 

  • 6 months later...
Posted
On 12/09/2025 at 11:52, synaesthesia said:

No, the machine is set up identically to every other staff device. Transparent proxy. 

Hi, did you ever get a resolution to this, I have two users with this exact issue.

 

Thanks

 

Jon

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...