Tek-Tips is the largest IT community on the Internet today!

Members share and learn making Tek-Tips Forums the best source of peer-reviewed technical information on the Internet!

  • Congratulations strongm on being selected by the Tek-Tips community for having the most helpful posts in the forums last week. Way to Go!

Admin Account Lockout

Status
Not open for further replies.

AuntieEPO

Technical User
Jul 3, 2002
61
GB
On our NT domain we have begun to experience the frequent (multiple times daily) lockout of out network administrator user.

Looking at the Security logs for Event ID's 644 it seems aparant that the source workstations are 3 different Server boxes within our LAN, this is happening randomly but multiple times a day.

Having searched around the three cuplrit servers we've eliminated the possibility that any drive mapping or services with the wrong credentials could be causing the issue - no one else can or will access these servers other than our 2 admins.

We temporarily renamed the admin account and this stopped it from locking out.

Now then, to try and make a contingency for the weekend, so that backup jobs and [rocesses etc etc would cont inue to run over the weekend, we set the bad logon threshold to 600 (during thursday/friday we had no more than 20 instances of the lockout occuring, with corresponding Event 644's each time appearing in the logs).

Lo and behold this morning we found the admin account to be locked out, but strangely there was only 1 Event Id 644 in the log, from friday evening - where I would have expected to see 600 of them.

Again, within 90 mins of me unlocking the account again this morning we have had another lockout with only one 644 displaying in the log.

Anyone any ideas where to go with this?
 
my mistake - i shouldnt expect 600 instances of 644, my NT knowledge is a little rusty and I presumed these were bad logon attempts when they areof course lock out notifications.

Bottom line is were aparantly having 600 failed attempt within 90 mins when our network is at its least populated in terms of user's acitve (friday evening and pre 9am monday).

Cant seem to pinpoint the cause, only the source(s)
 
Have you recently changed the admin password?
Are you running any services using that account?

At a guess I would say that you have a service running on these machines that has old credentials that's causing the lock outs.

As far as backups etc are concerned, you really should be using a dedicated backup user rather than the domain admin account.

I would start looking at your services and their corresponding service accounts.

Simon

The real world is not about exam scores, it's about ability.

 
Wow... ummm ok.

Simon

The real world is not about exam scores, it's about ability.

 
Status
Not open for further replies.

Part and Inventory Search

Sponsor

Back
Top