I have a user that keeps getting his account locked out. I was able to use the tools lockout status and EventCombMT to narrow some "things" down. I am still not sure what is causing this...
Here is from EventCombMT
672,AUDIT FAILURE,Security,Tue Sep 20 10:20:08 2011,NT AUTHORITY\SYSTEM,Authentication Ticket Request: User Name: john Supplied Realm Name: (MYDOMAIN) User ID: - Service Name: krbtgt/(MYDOMAIN) Service ID: - Ticket Options: 0x40810010 Result Code: 0x12 Ticket Encryption Type: - Pre-Authentication Type: - Client Address: 192.168.0.XXX Certificate Issuer Name: Certificate Serial Number: Certificate Thumbprint:
The above IP address is my Exchange server...
675,AUDIT FAILURE,Security,Tue Sep 20 09:00:59 2011,NT AUTHORITY\SYSTEM,Pre-authentication failed: User Name: john User ID: %{S-1-5-21-1074559079-462299982-911163043-1339} Service Name: krbtgt/(MYDOMAIN) Pre-Authentication Type: 0x2 Failure Code: 0x12 Client Address: 192.168.0.XX Certificate Issuer Name: %7 Certificate Serial Number: %8 Certificate Thumbprint: %9
The above is my DC.
Now on The LOCKOUTSTATUS, I have to DC's, one of them has the globe in the background, which I assume is the Global Catalog Server...
I have been working on this issue for a little while, I need some assistance...
Here is from EventCombMT
672,AUDIT FAILURE,Security,Tue Sep 20 10:20:08 2011,NT AUTHORITY\SYSTEM,Authentication Ticket Request: User Name: john Supplied Realm Name: (MYDOMAIN) User ID: - Service Name: krbtgt/(MYDOMAIN) Service ID: - Ticket Options: 0x40810010 Result Code: 0x12 Ticket Encryption Type: - Pre-Authentication Type: - Client Address: 192.168.0.XXX Certificate Issuer Name: Certificate Serial Number: Certificate Thumbprint:
The above IP address is my Exchange server...
675,AUDIT FAILURE,Security,Tue Sep 20 09:00:59 2011,NT AUTHORITY\SYSTEM,Pre-authentication failed: User Name: john User ID: %{S-1-5-21-1074559079-462299982-911163043-1339} Service Name: krbtgt/(MYDOMAIN) Pre-Authentication Type: 0x2 Failure Code: 0x12 Client Address: 192.168.0.XX Certificate Issuer Name: %7 Certificate Serial Number: %8 Certificate Thumbprint: %9
The above is my DC.
Now on The LOCKOUTSTATUS, I have to DC's, one of them has the globe in the background, which I assume is the Global Catalog Server...
I have been working on this issue for a little while, I need some assistance...