Warning: iconv_mime_decode() [function.iconv-mime-decode]: Malformed string in /home/secureg/public_html/lib/standard.lib.php on line 2251
User unlocking a locked account while bypassing the audit.
User unlocking a locked account while bypassing the audit.

User unlocking a locked account while bypassing the audit.

Secure Home | Search | About
 Microsoft Applications Security    Post an article   get this group's latest topics as an RSS feed add this group's latest topics to your My MSN content add this group's latest topics to your My Yahoo content add this group's latest topics to your Google content
Subject Author Date
User unlocking a locked account while bypassing the audit. mentesh 04-24-2006
Posted by on April 24, 2006, 7:22 pm
If you were  Registered and logged in, you could reply and use other advanced thread options
Hi all,

The problem is a user in a Windows 2000 AD environment that has his
account repeatedly keeps locking. Audit Account Management is on, and
the lockings appear in the log.

Somehow, the user is able to unlock the account by himself, and not
only that - the unlocking DOES NOT appear in the audit log (when I
unlock the account, it does appear in the log).

Can anyone please tell me how the hell is he doing that?

I'd appreciate any piece of advice...

Thanks
Tal


Posted by =?Utf-8?B?RGFu?= on April 24, 2006, 7:38 pm
If you were  Registered and logged in, you could reply and use other advanced thread options
Hi,

Unless the user has permissions to unlock accounts, then he isn't
unlocking the account. Look at the account lockout configuration in the
security settings. There is a setting that controls how long an account
stays locked for. Is it possible that the timeout (ex. 30 minutes) is
expiring, and then they're logging in?

To troubleshoot the account lockout, Microsoft has the account lockout and
management tool
http://www.microsoft.com/downloads/details.aspx?FamilyID=7af2e69c-91f3-4e63-8629-b999adde0b9e&DisplayLang=en

Good luck,
Dan Holton

"mentesh@gmail.com" wrote:

> Hi all,
>
> The problem is a user in a Windows 2000 AD environment that has his
> account repeatedly keeps locking. Audit Account Management is on, and
> the lockings appear in the log.
>
> Somehow, the user is able to unlock the account by himself, and not
> only that - the unlocking DOES NOT appear in the audit log (when I
> unlock the account, it does appear in the log).
>
> Can anyone please tell me how the hell is he doing that?
>
> I'd appreciate any piece of advice...
>
> Thanks
> Tal
>
>

Similar ThreadsPosted
Clear User Name Field when Unlocking PC September 20, 2006, 5:47 pm
Account locked July 28, 2006, 5:28 pm
Account is always locked out August 16, 2006, 12:27 pm
Account should be locked out.....but isn't! August 20, 2007, 10:34 am
Re: Audit Account Management June 15, 2005, 1:15 am
Audit Account Management June 14, 2005, 2:19 pm
IUSER Account gets locked July 14, 2005, 2:32 pm
Locked out of Hotmail Account July 29, 2005, 1:57 pm
Account Locked out but Not Logs to Check December 28, 2006, 7:54 pm
User audit September 6, 2005, 5:02 am

The site map in XML format XML site map

Contact Us | Privacy Policy