Incredibly weird issue, Win 7 account locked out

Associate
Joined
13 Jun 2005
Posts
1,416
Location
West Midlands
Hi folks,

Ill dive straight in with this one as Ive been working on it since 9am today, with little progress.

I have USER A who's account locks out without them even being logged into their machine. The user changed their password yesterday as per company policy and since then it keeps locking out after 3-5 minutes.

Platform - WIN 7 Pro 64 Bit
Server - Win Server 2008 R2 Standard



I have done the following -

Cleared credential manager - NO DIFFERENCE
Reset IE and cleared personal details during reset - NO DIFFERENCE
Tested by logging onto another machine - NO JOY
Recreated their login profile - NO DIFFERENCE
Checked for logged on terminal services accounts - NONE LOGGED IN
Connected devices ie. iPad, iPhone, Android - NONE

I have checked on our DC's and have found the following -

- System

- Provider

[ Name] Microsoft-Windows-Security-Auditing
[ Guid] {54849625-5478-4994-A5BA-3E3B0328C30D}

EventID 4776

Version 0

Level 0

Task 14336

Opcode 0

Keywords 0x8010000000000000

- TimeCreated

[ SystemTime] 2014-01-14T12:43:53.301501000Z

EventRecordID 2042599718

Correlation

- Execution

[ ProcessID] 516
[ ThreadID] 29720

Channel Security

Computer XXXXXXDC02.XXXXXXXXXXXXXX.co.uk

Security


- EventData

PackageName MICROSOFT_AUTHENTICATION_PACKAGE_V1_0
TargetUserName USER A
Workstation XXXXXXXX
Status 0xc0000234

Kind of hit a brick wall now. Any ideas anyone?
 
Will try disabling OWA.

User does not login on any other machines, but will still check as sometimes they might hotdesk.

UPDATE: Disabled OWA. Made sure user was completely logged out. Reenabled their login. Waited for 5 minutes and checked on DC. Account locked out again :(
 
Last edited:
No, on your workstation. It's an admin tool - just input the account UID and it'll list the domain controllers and the time of the account lockout. From there on in just do the detective work above :)

Usually with us, it's the support staff who've left themselves logged in on an RDP session and the password expires or they reset it. The RDP session keeps locking their account out until I find it and force the session to logoff.

Remember - most environments that are serious about security require domain admin rights to log onto a domain controller or see the logs.

Fixed! User was rdp'd elsewhere. Thanks for Altools. Wife's contractions started soon as we fixed it :)
 
Back
Top Bottom