Wednesday, March 22, 2017

active directory - AD Account Got Locked Out

We have a service account in our AD environment (Windows 2003) got locked out frequently.


some background information:



  • Windows 2003 domain

  • the account is set to never expire

  • we never changed the password of this account

  • The interval between each time i unlock the account is totally random.


Sometimes, the account runs normally for a week or two without any problem; while some other time, it locks again one day after i unlock


At first, i thought the account might be used by a process or schedule job or something which has a misconfigured password. I checked security logs on all DCs but found nothing. I tried the Microsoft Account Lockout Tool as well, and no luck as well.


We checked internal network traffic (assuming if the lockout is triggered by a server/endpoint machine), but couldn't find any invalid login attempt using this account.


We have lots of other service accounts in the same AD environment, and none of them are having the same issue.


I'm really running out of clue .... any help is much appreciated!


Thanks a lot!

No comments:

Post a Comment

hard drive - Leaving bad sectors in unformatted partition?

Laptop was acting really weird, and copy and seek times were really slow, so I decided to scan the hard drive surface. I have a couple hundr...