Account Lockout event log only recorded ... sometimes

Account Lockout event log only recorded ... sometimes

Secure Home | Search | About
 Microsoft Applications Security    Post an article   get this group's latest topics as an RSS feed add this group's latest topics to your My MSN content add this group's latest topics to your My Yahoo content add this group's latest topics to your Google content
Subject Author Date
Account Lockout event log only recorded ... sometimes <-> 12-14-2007
Posted by on December 14, 2007, 12:33 pm
If you were  Registered and logged in, you could reply and use other advanced thread options
Hello,

I've got my policy set up on Account Management success and Failure and I
have been getting records in the event log when user accounts lock out (a
644 event) and I still get them, but it seems to be a hit-or-miss thing
recently. If I weren't getting any, I would think the policy wasn't right,
but it's an intermittent issue. I know about the event log bug, and I
archive the logs with a VBscript every night so they don't get too big and
start dropping them, but there is at least one account, and probably more,
that is not recording the event of its locking out, and I need to see those
so I can inform the developer the originating machine name.

Any ideas?



Posted by Meinolf Weber on December 15, 2007, 12:09 pm
If you were  Registered and logged in, you could reply and use other advanced thread options
Hello -,

Do you have more than one DC and check all of them?

Best regards

Meinolf Weber
Disclaimer: This posting is provided "AS IS" with no warranties, and confers
no rights.
** Please do NOT email, only reply to Newsgroups
** HELP us help YOU!!! http://www.dts-l.org/goodpost.htm

> Hello,
>
> I've got my policy set up on Account Management success and Failure
> and I have been getting records in the event log when user accounts
> lock out (a 644 event) and I still get them, but it seems to be a
> hit-or-miss thing recently. If I weren't getting any, I would think
> the policy wasn't right, but it's an intermittent issue. I know about
> the event log bug, and I archive the logs with a VBscript every night
> so they don't get too big and start dropping them, but there is at
> least one account, and probably more, that is not recording the event
> of its locking out, and I need to see those so I can inform the
> developer the originating machine name.
>
> Any ideas?
>



Posted by on December 17, 2007, 10:59 am
If you were  Registered and logged in, you could reply and use other advanced thread options
Yes. I have checked the logs on all 7 DC's in the domain right after I see
that it's locked, and there's no 644 or 642 on that account on any of the 7
DC's. There are other accounts with 644's and 642's but not this one.


> Hello -,
>
> Do you have more than one DC and check all of them?
>
> Best regards
>
> Meinolf Weber
> Disclaimer: This posting is provided "AS IS" with no warranties, and
> confers no rights.
> ** Please do NOT email, only reply to Newsgroups
> ** HELP us help YOU!!! http://www.dts-l.org/goodpost.htm
>
>> Hello,
>>
>> I've got my policy set up on Account Management success and Failure
>> and I have been getting records in the event log when user accounts
>> lock out (a 644 event) and I still get them, but it seems to be a
>> hit-or-miss thing recently. If I weren't getting any, I would think
>> the policy wasn't right, but it's an intermittent issue. I know about
>> the event log bug, and I archive the logs with a VBscript every night
>> so they don't get too big and start dropping them, but there is at
>> least one account, and probably more, that is not recording the event
>> of its locking out, and I need to see those so I can inform the
>> developer the originating machine name.
>>
>> Any ideas?
>>
>
>



Similar ThreadsPosted
Account is unlocked but no 671 event is recorded August 7, 2006, 6:10 am
Account lockout October 20, 2006, 4:22 am
Account Lockout threshold June 12, 2005, 11:31 pm
Account Lockout Policies August 30, 2007, 1:14 am
Re: Account Lockout Policies September 4, 2007, 12:45 am
Administrator account and lockout policy July 15, 2008, 12:35 pm
User account lockout connecting to Exchange August 22, 2007, 12:28 pm
Event 539 with computer$ account August 2, 2006, 12:26 pm
Event ID 537 in Security Log for admin account June 12, 2007, 1:28 pm
Changing lockout in XP Pro SP 2 January 9, 2007, 9:05 pm

The site map in XML format XML site map

Contact Us | Privacy Policy