Domain user is locking his user account- but I cannot figger out why!?

I have a user, the CTO, who recently received a newly imaged workstation/notebook. He is using the same password for the last few password changes (this is between you and I!) but strangely, his user account has been locking on an irregular basis.I took
his machine out of the domain, renamed it and added it back to the domain and it seems to have been working fine for the last two weeks until the user came back from OS, connected to the local network (same domain) and his account started locking again.
I'm at my wits end here and cannot find the problem.
Here's what I've done so far:
* Removed all cached credentials from the workstation- from the browser and from the local computer cache.
* Checked for mapped drives- none found.
Here's what I've found so far:
* When his account locks, LockOutStatus shows his account has locked on the local AD server AD01.
Checking the Security log, I found the following:
Log Name:      Security
Source:        Microsoft-Windows-Security-Auditing
Date:          27/05/2014 12:07:40 PM
Event ID:      4776
Task Category: Credential Validation
Level:         Information
Keywords:      Audit Failure
User:          N/A
Computer:      AD01.mydomain.com
Description:
The computer attempted to validate the credentials for an account.
Authentication Package:    MICROSOFT_AUTHENTICATION_PACKAGE_V1_0
Logon Account:    hisusername
Source Workstation:    
Error Code:    0xc000006a
Event Xml:
<Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
  <System>
    <Provider Name="Microsoft-Windows-Security-Auditing" Guid="{54849625-5478-4994-A5BA-3E3B0328C30D}" />
    <EventID>4776</EventID>
    <Version>0</Version>
    <Level>0</Level>
    <Task>14336</Task>
    <Opcode>0</Opcode>
    <Keywords>0x8010000000000000</Keywords>
    <TimeCreated SystemTime="2014-05-27T02:07:40.997393300Z" />
    <EventRecordID>469726292</EventRecordID>
    <Correlation />
    <Execution ProcessID="532" ThreadID="5952" />
    <Channel>Security</Channel>
    <Computer>AD01.mydomain.com</Computer>
    <Security />
  </System>
  <EventData>
    <Data Name="PackageName">MICROSOFT_AUTHENTICATION_PACKAGE_V1_0</Data>
    <Data Name="TargetUserName">hisusername</Data>
    <Data Name="Workstation">
    </Data>
    <Data Name="Status">0xc000006a</Data>
  </EventData>
</Event>
Log Name:      Security
Source:        Microsoft-Windows-Security-Auditing
Date:          27/05/2014 12:07:40 PM
Event ID:      4740
Task Category: User Account Management
Level:         Information
Keywords:      Audit Success
User:          N/A
Computer:      AD01.mydomain.com
Description:
A user account was locked out.
Subject:
    Security ID:        SYSTEM
    Account Name:        AD01$
    Account Domain:        mydomain
    Logon ID:        0x3e7
Account That Was Locked Out:
    Security ID:        mydomain\hisusername
    Account Name:        hisusername
Additional Information:
    Caller Computer Name:    
Event Xml:
<Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
  <System>
    <Provider Name="Microsoft-Windows-Security-Auditing" Guid="{54849625-5478-4994-A5BA-3E3B0328C30D}" />
    <EventID>4740</EventID>
    <Version>0</Version>
    <Level>0</Level>
    <Task>13824</Task>
    <Opcode>0</Opcode>
    <Keywords>0x8020000000000000</Keywords>
    <TimeCreated SystemTime="2014-05-27T02:07:40.981770400Z" />
    <EventRecordID>469726291</EventRecordID>
    <Correlation />
    <Execution ProcessID="532" ThreadID="5952" />
    <Channel>Security</Channel>
    <Computer>AD01.mydomain.com</Computer>
    <Security />
  </System>
  <EventData>
    <Data Name="TargetUserName">hisusername</Data>
    <Data Name="TargetDomainName">
    </Data>
    <Data Name="TargetSid">S-1-5-21-1469019637-268265805-317593308-17583</Data>
    <Data Name="SubjectUserSid">S-1-5-18</Data>
    <Data Name="SubjectUserName">AD01$</Data>
    <Data Name="SubjectDomainName">mydomain</Data>
    <Data Name="SubjectLogonId">0x3e7</Data>
  </EventData>
</Event>
As you can see, there's no workstation name, which is strange to me.
I enabled debug logging with Netlogon (http://support.microsoft.com/kb/109626/en-us) but there is no entry for this specific time period.
The local Event Viewer | Security shows a number of failed audits, but nothing which seems to have anything to do with locking the account. Most of these are error 5152 (Filtering Platform Packet Drop), 5156 (Filtering Platform Connection) & 5157 (Filtering
Platform Connection) errors. I can detail these if you need me to, just let me know.
Can anyone suggest what else I can do?

Hi,
Please let me know the windows servers in your environment like Windows 2000, 2003, 2008 etc.
This is because , if you have set a GPO on your 2000 server, which is set to "Send NTLMv1" and the GPO on your Windows 2008 server is set to "Only accept NTLMv2." 
Checkout the below thread on similar discussion,
http://serverfault.com/questions/432280/password-authentication-fails-ntlmv2
Also checkout the below thread on audit failure with no workstation details,
http://social.technet.microsoft.com/Forums/windowsserver/en-US/3c1e1e0a-be1a-4529-b99e-99f8559114c5/evid-4776-can-see-user-name-but-no-workstation?forum=winserversecurity
Regards,
Gopi
JiJi
Technologies

Similar Messages

  • My Canon MP620 appears to be connected, yet every time I try to print something, it says error.  I have tried to unplug and track the error, but I cannot figure out why. Please help! this is such an inconvenience!

    My Canon MP620 appears to be connected, yet every time I try to print something, it says error.  I have tried to unplug and track the error, but I cannot figure out why. Please help! this is such an inconvenience!

    What Mac model? What Mac OS version?
    FYI, this forum is for Apple hardware made before 1999.

  • Apple ID issues? i think i have two accounts but i cannot find out the password for the one that controols my apps!? please help!

    I think I have two apple ID accounts.
    The account I am using right now is Alexiaann22. Im like 99.9999% possitive that before this was my origonal account(rosepetttals).
    When I am buying an app in the app store the apple id is already there and all you have to do is change the password. But the apple ID thaat is there is the Rosepetttals.
    I am no longer using that email so I cannot get the password sent to it. I also cannot retrieve the password for rosepetttals because it says that the birthday I am entering is incorrect. but im pretty sure I would know my own birthday.
    I know its alittle confusing but I would appreciate any feedback. Thanks you! 

    I am having this same issue, please help asap... I cannot listen to half of my music library and have never encountered this issue before.

  • My sons imessage on his IPOD is not sending or receiving for some reason. My Iphone and his brothers work. He is logged in to his Imessage account but he is not receiving or able to send.

    My sons imessage on his IPOD is not sending or receiving for some reason. My Iphone and his brothers work. He is logged in to his Imessage account but he is still not receiving or able to send and Imessage. Ive completed a re-start. I dont thik its his IPOD as his account on our family IMac is also not receiving or sending messages. Does anyone know what might be wrong?

    Has he tried connecting to a different network?
    Have you looked here:
    iOS: Troubleshooting Messages
    Has he went to Settings>Messages>Send and Receive and signed out and then back in?

  • I bought a used iPod and they were previously signed onto their iCloud. I have been wanting to change it but I have not been able to sign out of the previous account because I cannot sign out of "Find My iPod Touch". How am I able to log that off?

    I bought a used iPod and they were previously signed onto their iCloud account. I have been wanting to change it but I have not been able to sign out of the previous account because I cannot sign out of "Find My iPod Touch" due to not knowing the password. How am I able to shut that off and log into my own account?

    You can't.  This is a security feature to prevent the resale of stolen iOS devices.  You need to contact the seller and have him/her remove it from their iCloud account.  Or return and get your money back.  See: Find My iPhone Activation Lock - Apple Support

  • I bought an iphone and the guy has not used it in a year now i need to activate it and its linked to his icloud account so i cannot turn the phone on what can i do ???

    i bought an iphone and the guy has not used it in a year now i need to activate it and its linked to his icloud account so i cannot turn the phone on what can i do ???

    Here's what you can do:
    Find My iPhone Activation Lock: Removing a device from a previous owner’s account
    If you can't get the info needed, you can't use the device, sorry.

  • How do we change itune and icloud accounts?  My wife and I have seperate accounts but she cannot access hes, only mine.  This causes many issues like facetime, text etc. Do we have to reset her devices and start fresh?

    How do we change itune and icloud accounts?  My wife and I have separate accounts but she cannot access hes, only mine.  This causes many issues like face time, text etc. Do we have to reset her devices and start fresh?

    I think this may be the answer.
    http://support.apple.com/kb/HT5621

  • TS2446 i cant remember the answers to my security questions.  i have reset my password and added the recovery email account but still cant figure out how to purchase new content. it asks me the same security questions. how do i fix this?

    i cant remember the answers to my security questions.  i have reset my password and added the recovery email account but still cant figure out how to purchase new content. it asks me the same security questions. i also have a temp pin. how do i fix this?

    If you've just added an address to your account then it will be an alternate/secondary email address, a rescue email address can only be added by answering 2 of your security questions. If you already had one on your account then go to https://appleid.apple.com/ and click 'Manage your Apple ID' on the right-hand side of that page and log into your account. Then click on 'Password and Security' on the left-hand side of that page and on the right-hand side you should see an option to send security question reset info to your rescue email address.
    If you don't have a rescue email addressthen you will need to contact iTunes Support / Apple to get the questions reset.
    Contacting Apple about account security : http://support.apple.com/kb/HT5699
    When they've been reset (and if you don't already have a rescue email address) you can then use the steps half-way down this page to add a rescue email address for potential future use : http://support.apple.com/kb/HT5312

  • I recovered my stolen iPhone 4s thru' IMEI tracking and Police's help. The thief had set up the phone with his apple account. He is now out of police's contact and i could not retrieve his Apple/icloud PASSWORD which i need to ACTIVATE my iPhone. Any way?

    i recovered my stolen iPhone 4s thru' IMEI tracking and Police's help. The thief had set up the phone with his apple account. He is now out of police's contact and i could not retrieve his Apple/icloud PASSWORD which i need to ACTIVATE my iPhone. Any way?

    No, not without help from the thief.

  • I need to cancel my account, but I cannot verify my identity over the phone

    I need to cancel my account, but I cannot verify my identity over the phone as I do not know what pin I entered, or what security answer I put in, and of course there are no recent numbers in my phone, but I'm still me, and I'm still the one who pays my bill, and I still need to close my account, and I need a way to do that. Honestly I'm getting quite frustrated here and am considering starting a lawsuit or submitting my story to a newspaper, I like verizon and thought I would get my next phone under verizon as well, but now I'm not so sure. But whatever the the case, even if I need to go somewhere in person with my id to prove that I'm the owner of my account, I need it closed.
    I really hope that someone here can help me solve this issue, or direct me to someone who can solve this issue for me. I think that the better business bureau would find it as atrocious as I do that a person could get looped into payments that they don't want and cannot get out of, now I know that this was not the intention, but I really do need to cancel my plan because I cannot afford the bill.

    How To: Direct Message  and  AyaniB_VZW

  • HT3529 How do I send a group text, I have set up groups in my gmail account but can't figure out how to send a group text without adding them all individually

    How do I send a group text message, I have groups set up in my gmail account but can't figure out how to send a group text without adding them all individually ?

    You can use iCloud:
    Step 1. Log into www.icloud.com using your Apple ID.
    Step 2. Click on Contacts and then click the groups ribbon (the red icon with two people) which is on the left-hand page when viewing All Contacts.
    Step 3. The left page changes to a list of Groups (only those groups stored in iCloud are shown). Click the + button at the bottom to add a new group.
    Step 4. Type a name for the new group and press Enter to save it. To change it after this, double-click its entry in the groups list.
    Step 5. To add contacts to the new group, click on the All Contacts group and locate the first person to be added (you can use the search bar to find them quickly).
    Step 6. Drag their name on top of the new group and drop it to add it to that group.
    Step 7. To add more contacts, repeat steps 5 and 6, but you can add multiple contacts at once by pressing Ctrl (on a PC) or Command (on a Mac) and clicking on each contact in the list that you wish to select. Then, drag one of the highlighted names to the new group and they will all be added.
    It's possible to add names to more than one group, and you can create as many groups as you like.
    Step 8. Launch the Contacts app on your device (iPhone, iPod touch or iPad) and you should see the new group appear almost immediately - as long as you have an internet connection.
    Until Apple builds in a function to create groups directly within the Contacts app, this is the best way to do it.

  • HT1491 I have ten dollars in my account but i cant figure out how to use it to buy a cd?

    I have ten dollars in my account but i cant figure out how to use it to buy a cd?

    You can't.  The iTunes Store does not sell CDs.  The music it sells comes as downloadable music files.
    If that is what you want, just search in the Store for what you want, and then click Buy.  Note that the Store will collect sales tax.  The amount depends on where you live, but in most places, you cannot buy a $9.99 album for $10 since the sales tax will put you over.

  • HT4436 I want to Change the Full Name on my ICloud Mail Account, but I cannot Change it. Any Solution ?

    Dear All,
    I need to change the Full Name on my Icloud E-Mail Account, but I cannot change it, Any Solution ?
    Tanguy

    Go to icloud.com >> mail >> gear in the upper right >> preferences >> accounts.  You can change it there.  In my testing, I had to close and reopen my mail.app for it to take affect.

  • IPod is in Recovery Mode and when I Try to connect my itouch it says it cannot connect because it is locked with a password, but I cannot unlock it since it is in recovery mode! Help!! Pleaseee

    iPod is in Recovery Mode and when I Try to connect my itouch it says it cannot connect because it is locked with a password, but I cannot unlock it since it is in recovery mode! Help!! Pleaseee

    Try putting it in DFU mode and then restore.
    Basic troubleshooting steps  
    17" 2.2GHz i7 Quad-Core MacBook Pro  8G RAM  750G HD + OCZ Vertex 3 SSD Boot HD 
    Got problems with your Apple iDevice-like iPhone, iPad or iPod touch? Try Troubleshooting 101

  • It sounds stupid but I cannot figure out how to create a TOC

    It sounds stupid but I cannot figure out how to create a TOC

    You'll find some good video tutorials with these Google searches:
    (search Google for these terms without quotes)
    * indesign paragraph styles tutorial
    * indesign table of contents tutorial
    * InDesign paragraph styles in table of contents tutorial
    The simple principle is: InDesign creates a TOC by "pulling out" heading paragraphs from your document. To help it know which paragraphs are the headings you want in the TOC, you need to create paragraph styles, and apply them to the heading paragraphs. Then, when you perform Layout > Table of Contents, you choose the heading paragraph styles, and run the process.
    It may be daunting if you've never done anything like this. But, if you've done it in MS Word or other word processor, the principle is the same - make the headings identifiable in some way, so the software can extract them.
    Look at the video tutorials, create a heading paragraph style, create a TOC, and let us know the result.
    If your document is one of several that are gathered into an InDesign book, search Google for terms like "working with InDesign books tutorial," and "InDesign book table of  contents tutorial," without quotes.
    It would help if you can provide screen shots of your result. Search Google for terms like "how to create a screen shot on mac," or "how to create a screen sot on windows," without quotes. It also helps to display hidden characters when you make the screen shots. Search Google for terms like "how to display InDesign hidden characters," without quotes. Search Google for terms like "how to post a screen shot on an adobe user forum," without quotes.
    HTH
    Regards,
    Peter
    Peter Gold
    KnowHow ProServices

Maybe you are looking for