Jump to content

Recommended Posts

Posted (edited)

Hi All,

I have one user who's AD account is randomly locking out. It's not consistently locking out just randomly every couple of days and some days several times per day. I am going to delete her user profile and have downloaded the M$ Account Lockout Tool and am hoping that it's more useful than event logs! Those error codes are not particularly helpful in my experience as they are so broad!

 

Just wondered if anyone can give me a list of things to check or if anyone has experienced random lockouts affecting a single user. I can't imagine that there are any issues with AD, as loads of teachers would reporting that their accounts are locking randomly! We don't run RADIUS or anything similar.

 

Thanks in advance.

 

 

Edited by cheaptonersucks
Posted (edited)

The lockout tool will point to a specific DC if you have mulltiple then search that DC event logs for the user and hopefully this will indicate an IP address of the source.

 

Been down this road many times before and it was one of 2 things either an App/service using old password or a PC where user was still logged into.

 

Do you allow user switching on PCs?

 

Can you ask user how recently they changed their password?

Edited by Davit2005
  • Like 1
Posted (edited)
18 minutes ago, cheaptonersucks said:

Thanks guys!! The user does tend to leave her office PC logged in and then login in her classroom, although other staff do this and their accounts don't lockout??

A logged in account will use old password, the other more troubling thought is a tried forced attempt on the account.

 

Look at all the services you may provide including cloud, VPN, etc. Search those logs too.

Edited by Davit2005
  • Like 1
Posted

Thanks guys. Other staff 'forget' to logoff from their office PC and login to the classroom PC but don't get locked out so there must be something different that this member of staff has done recently... I hope that it's not a brute force attack!! 😱

Posted (edited)
26 minutes ago, cheaptonersucks said:

Thanks guys. Other staff 'forget' to logoff from their office PC and login to the classroom PC but don't get locked out so there must be something different that this member of staff has done recently... I hope that it's not a brute force attack!! 😱

Do PCs regularly reboot. One thing we implemented at a previous place was a nightly reboot of all PCs and it reduced these issues to very nearly zero. Outlook app was another one that regularly caused it.

Edited by Davit2005
  • Like 1
Posted

There is a pwdLastSet attribute in AD 

There is also a badPassWord time too 

if they have an unusual mapped drive might cause the issue too 

  • Like 1
Posted (edited)

Thanks guys. I should have mentioned that all of the teaching PCs are desktops with wired connections. The school PCs are shut down every Friday so not that often. Is it best to tell staff to remove the Outlook app? Most staff use the app though and it's just this teacher that is experiencing random lockouts this week.

Edited by cheaptonersucks
Posted
On 27/02/2026 at 14:46, cheaptonersucks said:

Thanks guys. I should have mentioned that all of the teaching PCs are desktops with wired connections. The school PCs are shut down every Friday so not that often. Is it best to tell staff to remove the Outlook app? Most staff use the app though and it's just this teacher that is experiencing random lockouts this week.

There is no need to stop using the outlook app, you could have the same problem if a user changes password whilst still logged into a PC.

 

AD if used is a good start for investigating as that's what they are authenticating against 🙂 That will likely show source IP.

 

 

  • Like 1
  • 3 weeks later...
Posted

Two more users whose AD accounts are locking out now. Never experienced this before. Asked users to remove Outlook app to no avail. Not all users affected and all are authenticating against the same domain controllers. 

Posted
2 minutes ago, cheaptonersucks said:

Two more users whose AD accounts are locking out now. Never experienced this before. Asked users to remove Outlook app to no avail. Not all users affected and all are authenticating against the same domain controllers. 

You jus need to look at the available logs and see where they are getting locked out from. Use the sysinternals lockout tool to identify what domain controller they are locked out on then check event logs of that DC.

  • Like 1
Posted
12 minutes ago, Davit2005 said:

Use the sysinternals lockout tool to identify what domain controller they are locked out on then check event logs of that DC.

I've known  about and used sysinternals suite at least monthly since the early 00's. How did I not know about that tool?

  • Like 2
Posted (edited)
15 minutes ago, Davit2005 said:

... then check event logs of that DC.

@cheaptonersucks fi you haven't already you will need to turn on some advanced auditing options to be sure the event logs are getting the info you need.

Edited by psydii
  • Like 2
Posted
Just now, cheaptonersucks said:

Thanks. We downloaded the account lockout status tool but these tools just tell you that the account is locked out and the domain controller. They don't actually tell you why the accounts are locking out.

 

Download Account Lockout Status (LockoutStatus.exe) from Official Microsoft Download Center

Check security events on the DC listed. Look for IP addresses or sources, then identify the service where user is getting locked out.

  • Like 1
Posted
1 minute ago, psydii said:

I've known  about and used sysinternals suite at least monthly since the early 00's. How did I not know about that tool?

Yep it really helped us when we had exchange, I think every time it was either exchange or user had changed password whilst logged onto another PC. The forced shutdown of PCs every night helped a lot too.

  • Like 1
Posted

And you are sure there is not a user on your domain doing this on purpose?

Has the user who is being locked out and another user got very similar logon names?

 

  • Like 2
Posted
2 minutes ago, kennysarmy said:

And you are sure there is not a user on your domain doing this on purpose?

Has the user who is being locked out and another user got very similar logon names?

 

Indeed, the playful minds of students. Reminds me of a call I had many years back in a school. Ticket jus said it keeps turning off when I log in. Turned out the little rascals were switching off the power switch (located by a front desk) when they saw the teacher logging in, lol.

  • Like 1
  • Haha 1
Posted

It's only affecting 4 staff at the moment thankfully. No students are being affected and the staff don't have any similarities in terms of names etc. I have checked the logs and it's not user error, so it's not that they are getting their passwords wrong. Their accounts are weirdly locking out 'sometimes' when they have been logged in for a while??  It's very random as one teacher didn't have a single lockout all day yesterday?? The affected users can go most of the day of logging in and out with no lockouts??

 

Downloaded ADAudit Plus and caller machine name for each user that is being locked out is the same DC. Worryingly the Administrator account is locking out as well. It's an outstanding grammar school and we don't ever have any issues with students messing around thankfully.

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...