hidden hit counter
Help!

How to check bad password login in Windows 2003 domain con..

 
  

Post new topic   General Reply to Topic (not reply to a specific post)    Forums Home -> Active Directory RSS
Next:  What if you were only .00005% successful  
Author Message
Will
External


Since: Jun 01, 2009
Posts: 1



PostPosted: Mon Jun 01, 2009 12:10 pm    Post subject: How to check bad password login in Windows 2003 domain controller?
Archived from groups: microsoft>public>win2000>active_directory (more info?)

User report their user account always locked. But I cannot found any bad
password & account locked event in the domain controller secuirty event log,
even I enable audit log in domain policy.

How to check bad password login in Windows 2003 domain controller?

Thanks
Back to top
Richard Mueller [MVP]
External


Since: Feb 25, 2007
Posts: 33



PostPosted: Mon Jun 01, 2009 12:10 pm    Post subject: Re: How to check bad password login in Windows 2003 domain controller? [Login to view extended thread Info.]
Archived from groups: per prev. post (more info?)

"Will" <william.TakeThisOut@live.com> wrote in message
news:7C65B787-BECE-4345-AE4E-B47823873E47@microsoft.com...
> User report their user account always locked. But I cannot found any bad
> password & account locked event in the domain controller secuirty event
> log, even I enable audit log in domain policy.
>
> How to check bad password login in Windows 2003 domain controller?
>
> Thanks

The information is not replicated between DC's, so you need to look on the
DC (or DC's) that authenticated the user. I think there is tool to retrieve
information about locked out accounts, but I cannot find information on it.
However, I have an example VBScript program to retrieve information on all
locked out users linked here:

http://www.rlmueller.net/LockedUsers.htm

The program contacts all Domain Controllers to get the information, so it
can take awhile in a large network with slow connections. One of the
purposes is to identify the DC autenticating the locked out users.

Note that common causes are scheduled tasks or services that attempt to
authenticate with old credentials. Also, persistent drive mappings to shares
that require passwords can cause this.

--
Richard Mueller
MVP Directory Services
Hilltop Lab - http://www.rlmueller.net
--
Back to top
Display posts from previous:   
Post new topic   General Reply to Topic (not reply to a specific post)    Forums Home -> Active Directory All times are: Eastern Time (US & Canada) (change)
Page 1 of 1

 
You can post new topics in this forum
You can reply to topics in this forum
You can edit your posts in this forum
You can delete your posts in this forum
You can vote in polls in this forum