Advertisement
Help Keep Boards Alive. Support us by going ad free today. See here: https://subscriptions.boards.ie/.
If we do not hit our goal we will be forced to close the site.

Current status: https://keepboardsalive.com/

Annual subs are best for most impact. If you are still undecided on going Ad Free - you can also donate using the Paypal Donate option. All contribution helps. Thank you.
https://www.boards.ie/group/1878-subscribers-forum

Private Group for paid up members of Boards.ie. Join the club.

Active Directory (Windows)

  • 10-12-2009 01:15PM
    #1
    Registered Users, Registered Users 2 Posts: 74 ✭✭


    Hi All,

    Just wondering if anyone knows about event ID'd within security log of 2003 server? I ma trying to audit bad passwords on our network Event ID 675. When a user enters a bad password loggin onto a machine it triggers event id 675 with service name krbtgt\domain, after 4 attempts they are locked out.

    However during the course off the day I am noticing the same event ID trigger maybe 20 times a day with no lockout. The only difference is the event ID has a service name of krbtgt\domain.net.local. Anyone know why their is a differnce in service names within the event ID?


Comments

  • Registered Users, Registered Users 2, Paid Member Posts: 7,226 ✭✭✭mada999


    grab altools from the web and use the 'LockoutStatus.exe' to find out what DC it is getting locked out from... check the event logs of hte DC to find out where the account is getting locked from

    happened me before... i had some stored cached credentials for RDP


  • Closed Accounts Posts: 17,208 ✭✭✭✭aidan_walsh


    Not really the right forum for this, as well as being ye olde bump.


This discussion has been closed.
Advertisement