cheaptonersucks Posted February 27 Posted February 27 (edited) Hi All, I have one user who's AD account is randomly locking out. It's not consistently locking out just randomly every couple of days and some days several times per day. I am going to delete her user profile and have downloaded the M$ Account Lockout Tool and am hoping that it's more useful than event logs! Those error codes are not particularly helpful in my experience as they are so broad! Just wondered if anyone can give me a list of things to check or if anyone has experienced random lockouts affecting a single user. I can't imagine that there are any issues with AD, as loads of teachers would reporting that their accounts are locking randomly! We don't run RADIUS or anything similar. Thanks in advance. Edited February 27 by cheaptonersucks
Davit2005 Posted February 27 Posted February 27 (edited) The lockout tool will point to a specific DC if you have mulltiple then search that DC event logs for the user and hopefully this will indicate an IP address of the source. Been down this road many times before and it was one of 2 things either an App/service using old password or a PC where user was still logged into. Do you allow user switching on PCs? Can you ask user how recently they changed their password? Edited February 27 by Davit2005 1
markwilfan Posted February 27 Posted February 27 Run this on a DC to find what is locking the account out get-winevent -FilterHashtable @{logname='security';id=4740} | fl 2
cheaptonersucks Posted February 27 Author Posted February 27 Thanks guys!! The user does tend to leave her office PC logged in and then login in her classroom, although other staff do this and their accounts don't lockout??
cheaptonersucks Posted February 27 Author Posted February 27 Do you allow user switching on PCs? No Can you ask user how recently they changed their password? It hasn't been changed for a very long time but I will find out...
kennysarmy Posted February 27 Posted February 27 We get this sometimes, have they set up O365 access on their phones and recently changed their password? 1
Davit2005 Posted February 27 Posted February 27 (edited) 18 minutes ago, cheaptonersucks said: Thanks guys!! The user does tend to leave her office PC logged in and then login in her classroom, although other staff do this and their accounts don't lockout?? A logged in account will use old password, the other more troubling thought is a tried forced attempt on the account. Look at all the services you may provide including cloud, VPN, etc. Search those logs too. Edited February 27 by Davit2005 1
cheaptonersucks Posted February 27 Author Posted February 27 Thanks, yes, the member of staff setup the Outlook app on her phone some time ago. She didn't say that she has changed her password recently but I will check.
cheaptonersucks Posted February 27 Author Posted February 27 Thanks guys. Other staff 'forget' to logoff from their office PC and login to the classroom PC but don't get locked out so there must be something different that this member of staff has done recently... I hope that it's not a brute force attack!! 😱
Davit2005 Posted February 27 Posted February 27 (edited) 26 minutes ago, cheaptonersucks said: Thanks guys. Other staff 'forget' to logoff from their office PC and login to the classroom PC but don't get locked out so there must be something different that this member of staff has done recently... I hope that it's not a brute force attack!! 😱 Do PCs regularly reboot. One thing we implemented at a previous place was a nightly reboot of all PCs and it reduced these issues to very nearly zero. Outlook app was another one that regularly caused it. Edited February 27 by Davit2005 1
machy Posted February 27 Posted February 27 There is a pwdLastSet attribute in AD There is also a badPassWord time too if they have an unusual mapped drive might cause the issue too 1
psydii Posted February 27 Posted February 27 Also can be caused by a device using the account to log on to wifi, but has the wrong/old password? 1
cheaptonersucks Posted February 27 Author Posted February 27 (edited) Thanks guys. I should have mentioned that all of the teaching PCs are desktops with wired connections. The school PCs are shut down every Friday so not that often. Is it best to tell staff to remove the Outlook app? Most staff use the app though and it's just this teacher that is experiencing random lockouts this week. Edited February 27 by cheaptonersucks
Davit2005 Posted March 2 Posted March 2 On 27/02/2026 at 14:46, cheaptonersucks said: Thanks guys. I should have mentioned that all of the teaching PCs are desktops with wired connections. The school PCs are shut down every Friday so not that often. Is it best to tell staff to remove the Outlook app? Most staff use the app though and it's just this teacher that is experiencing random lockouts this week. There is no need to stop using the outlook app, you could have the same problem if a user changes password whilst still logged into a PC. AD if used is a good start for investigating as that's what they are authenticating against 🙂 That will likely show source IP. 1
cheaptonersucks Posted March 24 Author Posted March 24 Two more users whose AD accounts are locking out now. Never experienced this before. Asked users to remove Outlook app to no avail. Not all users affected and all are authenticating against the same domain controllers.
Davit2005 Posted March 24 Posted March 24 2 minutes ago, cheaptonersucks said: Two more users whose AD accounts are locking out now. Never experienced this before. Asked users to remove Outlook app to no avail. Not all users affected and all are authenticating against the same domain controllers. You jus need to look at the available logs and see where they are getting locked out from. Use the sysinternals lockout tool to identify what domain controller they are locked out on then check event logs of that DC. 1
cheaptonersucks Posted March 24 Author Posted March 24 Thanks. We downloaded the account lockout status tool but these tools just tell you that the account is locked out and the domain controller. They don't actually tell you why the accounts are locking out. Download Account Lockout Status (LockoutStatus.exe) from Official Microsoft Download Center
psydii Posted March 24 Posted March 24 12 minutes ago, Davit2005 said: Use the sysinternals lockout tool to identify what domain controller they are locked out on then check event logs of that DC. I've known about and used sysinternals suite at least monthly since the early 00's. How did I not know about that tool? 2
psydii Posted March 24 Posted March 24 (edited) 15 minutes ago, Davit2005 said: ... then check event logs of that DC. @cheaptonersucks fi you haven't already you will need to turn on some advanced auditing options to be sure the event logs are getting the info you need. Edited March 24 by psydii 2
Davit2005 Posted March 24 Posted March 24 Just now, cheaptonersucks said: Thanks. We downloaded the account lockout status tool but these tools just tell you that the account is locked out and the domain controller. They don't actually tell you why the accounts are locking out. Download Account Lockout Status (LockoutStatus.exe) from Official Microsoft Download Center Check security events on the DC listed. Look for IP addresses or sources, then identify the service where user is getting locked out. 1
Davit2005 Posted March 24 Posted March 24 1 minute ago, psydii said: I've known about and used sysinternals suite at least monthly since the early 00's. How did I not know about that tool? Yep it really helped us when we had exchange, I think every time it was either exchange or user had changed password whilst logged onto another PC. The forced shutdown of PCs every night helped a lot too. 1
kennysarmy Posted March 24 Posted March 24 And you are sure there is not a user on your domain doing this on purpose? Has the user who is being locked out and another user got very similar logon names? 2
Davit2005 Posted March 24 Posted March 24 2 minutes ago, kennysarmy said: And you are sure there is not a user on your domain doing this on purpose? Has the user who is being locked out and another user got very similar logon names? Indeed, the playful minds of students. Reminds me of a call I had many years back in a school. Ticket jus said it keeps turning off when I log in. Turned out the little rascals were switching off the power switch (located by a front desk) when they saw the teacher logging in, lol. 1 1
cheaptonersucks Posted March 25 Author Posted March 25 It's only affecting 4 staff at the moment thankfully. No students are being affected and the staff don't have any similarities in terms of names etc. I have checked the logs and it's not user error, so it's not that they are getting their passwords wrong. Their accounts are weirdly locking out 'sometimes' when they have been logged in for a while?? It's very random as one teacher didn't have a single lockout all day yesterday?? The affected users can go most of the day of logging in and out with no lockouts?? Downloaded ADAudit Plus and caller machine name for each user that is being locked out is the same DC. Worryingly the Administrator account is locking out as well. It's an outstanding grammar school and we don't ever have any issues with students messing around thankfully.
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now