Jump to content

Recommended Posts

Posted
45 minutes ago, cheaptonersucks said:

It's only affecting 4 staff at the moment thankfully. No students are being affected and the staff don't have any similarities in terms of names etc. I have checked the logs and it's not user error, so it's not that they are getting their passwords wrong. Their accounts are weirdly locking out 'sometimes' when they have been logged in for a while??  It's very random as one teacher didn't have a single lockout all day yesterday?? The affected users can go most of the day of logging in and out with no lockouts??

 

Downloaded ADAudit Plus and caller machine name for each user that is being locked out is the same DC. Worryingly the Administrator account is locking out as well. It's an outstanding grammar school and we don't ever have any issues with students messing around thankfully.

Local Administrator account locked out or a domain admin account?

 

When you identify the DC then examine the logs you should search for the source. As @psydii mentions make sure all advanced auditing is enabled. I do think you need to rule out the source of the lockout before going much deeper though.

 

Is the domain admin account used on any services? Always found best to create a specific user account per service and give that only the access it needs. i.e. LDAP auth does not need domain admin, normally a standard domain user account will do the job.

 

 

  • Like 1
Posted

Thanks, it's the domain admin account.

 

The caller username is always the same DC and the caller machine name is always a different DC. The caller IP address is always the same. Is that not the source of the lockouts?

 

I will check with the NM if the admin account is used on any services as I don't know.

 

It's just odd that nothing has changed on the network as far as I am aware and only 4 out of 100 + staff are being affected. 1000 students are not being affected either so it very much confined to the domain admin account and 4 staff at the moment. It's changed slightly in that the 4 staff accounts affected randomly to only two staff accounts being locked today. Both of the staff accounts affected today have been locked out a while after they logged on.

ADAudit Plus.png

Posted (edited)

TBH I am not familiar with AD Audit Plus, I have always just used a combination of the lockout status tool and the security logs on the DC identified.

 

There is a way to check which process is locking out an account I believe.

 

 

 

 

 

Edited by Davit2005
Posted

Thanks, do you know how to check exactly why the accounts are locking in term of which process. I don't find logs that helpful at times as giving a machine name or a random code doesn't explain why something is occurring.

Posted (edited)
10 minutes ago, cheaptonersucks said:

Thanks, do you know how to check exactly why the accounts are locking in term of which process. I don't find logs that helpful at times as giving a machine name or a random code doesn't explain why something is occurring.

In the case of exchange it will likely be the name of the exchange server. In the case of a desktop you should get the same. I don't work in that area of support anymore to guide further. But it should hopefully give you an idea of where to start looking.

Edited by Davit2005
  • Like 1
  • 3 weeks later...
Posted

We had a similar issue a while ago, it was infuriating. using AD lockout we determined the user was trying to authenticate 50+ times a day. Turns out their AD password expired before maternity leave and upon coming back, her mobile phone was still trying to connect to the wifi with an old password.

 

Hope this helps.

  • Like 1
  • 2 weeks later...

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...