How to find what process is causing account lockout?

W

WorkingStiff

I set up account lockout policies to lock an account after several tries, but when I
changed my password, the account gets locked out constantly (though just retrying a few
times usually gets me in). I've turned on as many security logging options as I can find,
but no logs show what process is causing the lockout. This lockout occurs even if I
disconnect the machine from the network, so it must be a process on the local machine.

How can I find what process is causing the lockout?

Thanks
RDPfan
 
J

Jon Phipps

what is the account lockout threshold? If it is too low it will lock out as
soon as the password is blown once
 
W

WorkingStiff

Threshhold is actually high (about 20). I went through each service and found the ones
that were NT AUTHORITY/LocalService which had a password and changed them to the local
system acct and haven't had the problem since. I don't really understand what I did
exactly, but nothing has broken as far as I can tell so I guess this problem is solved.
thanks!
 

Ask a Question

Want to reply to this thread or ask your own question?

You'll need to choose a username for the site, which only take a couple of moments. After that, you can post your question and our members will help you out.

Ask a Question

Top