Trace locked out account

Viewing 1 post (of 1 total)
  • Author
  • Avatar

    Some dumb user’s account (um, it’s mine) gets locked out 2-3 times per day and I can’t get to the bottom of it.

    I’m a server admin so am constantly doing a lot of “stuff”. I do know my account is not associated with any services or scheduled tasks.

    If I run Microsoft’s lockoutstatus tool I do indeed see my account as locked out, and the DC’s that list a bad PW count, but the event logs on these or any of my DC’s show nothing.

    Via group policy we have ‘audit account logon events’ enabled for failures and ‘audit account logon’ fully enabled.

    Any hints on how to discover what box these bad pw attempts are coming from?

Viewing 1 post (of 1 total)

You must be logged in to reply to this topic.