Click here to get back home

Administrator account locking out

 HomeNewsGroups | Search | About
 microsoft.public.windows.server.security    Post an article   get this group's latest topics as an RSS feed add this group's latest topics to your My MSN content add this group's latest topics to your My Yahoo content
Subject Author Date
Administrator account locking out tfort 04-01-2006
Posted by tfort on April 1, 2006, 9:22 am
Please log in for more thread options
I have over the past 3 months had periods where my administrator
account would be locked out after we changed the password in January.
I figured it was some service that had the password saved and was
causing this. However, now, my admin account is being locked out as
quickly as it is unlocked. I turned on failure auditing and in the
security log I get these errors:

Event Type:        Failure Audit
Event Source:        Security
Event Category:        Account Logon
Event ID:        680
Date:                4/1/2006
Time:                9:15:31 AM
User:                NT AUTHORITY\SYSTEM
Computer:        EMJDC
Description:
Logon attempt by:        MICROSOFT_AUTHENTICATION_PACKAGE_V1_0
Logon account:        Administrator
Source Workstation:        workstation
Error Code:        0xC0000234

----------------------------------------------------------------------------------------------------------------------

Event Type:        Failure Audit
Event Source:        Security
Event Category:        Account Logon
Event ID:        673
Date:                4/1/2006
Time:                9:13:52 AM
User:                NT AUTHORITY\SYSTEM
Computer:        EMJDC
Description:
Service Ticket Request:
        User Name:                administrator@DOMAIN.COM
        User Domain:                DOMAIN.COM
        Service Name:                krbtgt/DOMAIN.COM
        Service ID:                -
        Ticket Options:                0x2
        Ticket Encryption Type:        -
        Client Address:                127.0.0.1
        Failure Code:                0x12
        Logon GUID:                -
        Transited Services:        -


It would appear that something/some service on my DC's is locking up my
admin account, but I can't seem to figure it out... Any help would be
appreciated!!
Tim


Posted by Roger Abell [MVP] on April 1, 2006, 12:53 pm
Please log in for more thread options
First, to get some temporary relief, rename your admin account.
Be aware of any scheduled tasks or services configured to run
as that account when doing so however.
Next, post some real info, as there is no way to see your conclusion
that something on that machine is causing the issue. (named both
workstation and also EMJDC is not possible)
There is a set of download tools from MS that can assist in
diag of account lockouts, but perhaps it is something more
simply located (again, real info would be great help).

>I have over the past 3 months had periods where my administrator
> account would be locked out after we changed the password in January.
> I figured it was some service that had the password saved and was
> causing this. However, now, my admin account is being locked out as
> quickly as it is unlocked. I turned on failure auditing and in the
> security log I get these errors:
>
> Event Type: Failure Audit
> Event Source: Security
> Event Category: Account Logon
> Event ID: 680
> Date: 4/1/2006
> Time: 9:15:31 AM
> User: NT AUTHORITY\SYSTEM
> Computer: EMJDC
> Description:
> Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0
> Logon account: Administrator
> Source Workstation: workstation
> Error Code: 0xC0000234
>
>
----------------------------------------------------------------------------------------------------------------------
>
> Event Type: Failure Audit
> Event Source: Security
> Event Category: Account Logon
> Event ID: 673
> Date: 4/1/2006
> Time: 9:13:52 AM
> User: NT AUTHORITY\SYSTEM
> Computer: EMJDC
> Description:
> Service Ticket Request:
> User Name: administrator@DOMAIN.COM
> User Domain: DOMAIN.COM
> Service Name: krbtgt/DOMAIN.COM
> Service ID: -
> Ticket Options: 0x2
> Ticket Encryption Type: -
> Client Address: 127.0.0.1
> Failure Code: 0x12
> Logon GUID: -
> Transited Services: -
>
>
> It would appear that something/some service on my DC's is locking up my
> admin account, but I can't seem to figure it out... Any help would be
> appreciated!!
> Tim
>



Posted by timpj5 on April 4, 2006, 11:17 am
Please log in for more thread options
I'm leary of renaming my admin account as there are a whole lot of
services that run as administrator on alot of different servers and
don't want to spend the entire week troubleshooting why a particular
service doesn't work. I'm not saying I won't do it if I have to, it's
just not something I'm really looking forward to.

That said, here is some real info... (sorry, I was trying to protect
the innocent in my previous post)

---------------------------------------------------------------------
Event Type:        Failure Audit
Event Source:        Security
Event Category:        Account Logon
Event ID:        675
Date:                4/4/2006
Time:                11:09:49 AM
User:                NT AUTHORITY\SYSTEM
Computer:        EMJDC
Description:
Pre-authentication failed:
        User Name:        administrator
        User ID:                EMJCORP\administrator
        Service Name:        krbtgt/emjcorp.com
        Pre-Authentication Type:        0x2
        Failure Code:        0x18
        Client Address:        192.168.155.10
-----------------------------------------------------------------------------------------
Event Type:        Failure Audit
Event Source:        Security
Event Category:        Account Logon
Event ID:        680
Date:                4/4/2006
Time:                10:55:52 AM
User:                NT AUTHORITY\SYSTEM
Computer:        EMJDC
Description:
Logon attempt by:        MICROSOFT_AUTHENTICATION_PACKAGE_V1_0
Logon account:        administrator
Source Workstation:        EMJSACRAMENTO
Error Code:        0xC0000234
------------------------------------------------------------------------------------------------------------
Event Type:        Failure Audit
Event Source:        Security
Event Category:        Account Logon
Event ID:        672
Date:                4/4/2006
Time:                10:06:08 AM
User:                NT AUTHORITY\SYSTEM
Computer:        EMJDC
Description:
Authentication Ticket Request:
        User Name:                administrator
        Supplied Realm Name:        EMJCORP
        User ID:                        -
        Service Name:                krbtgt/EMJCORP
        Service ID:                -
        Ticket Options:                0x40810010
        Result Code:                0x12
        Ticket Encryption Type:        -
        Pre-Authentication Type:        -
        Client Address:                192.168.135.10
        Certificate Issuer Name:
        Certificate Serial Number:
        Certificate Thumbprint:
----------------------------------------------------------------------------------------------------
Event Type:        Failure Audit
Event Source:        Security
Event Category:        Account Logon
Event ID:        673
Date:                4/4/2006
Time:                9:03:17 AM
User:                NT AUTHORITY\SYSTEM
Computer:        EMJDC
Description:
Service Ticket Request:
        User Name:                administrator@EMJCORP.COM
        User Domain:                EMJCORP.COM
        Service Name:                cifs/emjdc
        Service ID:                -
        Ticket Options:                0x40810000
        Ticket Encryption Type:        -
        Client Address:                192.168.125.202
        Failure Code:                0x12
        Logon GUID:                -
        Transited Services:        -
--------------------------------------------------------------------------------------------------------------------

I continue to have my admin account locked out and I believe it is
because of a service or program running under the old password, but
can't determine which service, program or machine. Thanks,
Tim


Posted by Roger Abell [MVP] on April 4, 2006, 11:36 am
Please log in for more thread options
The account named "Administrator" is unique per machine, except
for domain controllers where it is the same on them all.
If you have used the domain\Administrator account on machines
other than domain controllers keep in mind that this is not the
Administrators account defined on those machines.
So, by renaming you really only need to look at one machine,
or at the domain controllers, in order to see the scope of impact.
Go to microsoft.com/downloads and search on account lockout
as there is a package of utilities that can help you track down the
origin of the authentication attempts that are locking the account.

> I'm leary of renaming my admin account as there are a whole lot of
> services that run as administrator on alot of different servers and
> don't want to spend the entire week troubleshooting why a particular
> service doesn't work. I'm not saying I won't do it if I have to, it's
> just not something I'm really looking forward to.
>
> That said, here is some real info... (sorry, I was trying to protect
> the innocent in my previous post)
>
> ---------------------------------------------------------------------
> Event Type: Failure Audit
> Event Source: Security
> Event Category: Account Logon
> Event ID: 675
> Date: 4/4/2006
> Time: 11:09:49 AM
> User: NT AUTHORITY\SYSTEM
> Computer: EMJDC
> Description:
> Pre-authentication failed:
> User Name: administrator
> User ID: EMJCORP\administrator
> Service Name: krbtgt/emjcorp.com
> Pre-Authentication Type: 0x2
> Failure Code: 0x18
> Client Address: 192.168.155.10
>
-----------------------------------------------------------------------------------------
> Event Type: Failure Audit
> Event Source: Security
> Event Category: Account Logon
> Event ID: 680
> Date: 4/4/2006
> Time: 10:55:52 AM
> User: NT AUTHORITY\SYSTEM
> Computer: EMJDC
> Description:
> Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0
> Logon account: administrator
> Source Workstation: EMJSACRAMENTO
> Error Code: 0xC0000234
>
------------------------------------------------------------------------------------------------------------
> Event Type: Failure Audit
> Event Source: Security
> Event Category: Account Logon
> Event ID: 672
> Date: 4/4/2006
> Time: 10:06:08 AM
> User: NT AUTHORITY\SYSTEM
> Computer: EMJDC
> Description:
> Authentication Ticket Request:
> User Name: administrator
> Supplied Realm Name: EMJCORP
> User ID: -
> Service Name: krbtgt/EMJCORP
> Service ID: -
> Ticket Options: 0x40810010
> Result Code: 0x12
> Ticket Encryption Type: -
> Pre-Authentication Type: -
> Client Address: 192.168.135.10
> Certificate Issuer Name:
> Certificate Serial Number:
> Certificate Thumbprint:
>
----------------------------------------------------------------------------------------------------
> Event Type: Failure Audit
> Event Source: Security
> Event Category: Account Logon
> Event ID: 673
> Date: 4/4/2006
> Time: 9:03:17 AM
> User: NT AUTHORITY\SYSTEM
> Computer: EMJDC
> Description:
> Service Ticket Request:
> User Name: administrator@EMJCORP.COM
> User Domain: EMJCORP.COM
> Service Name: cifs/emjdc
> Service ID: -
> Ticket Options: 0x40810000
> Ticket Encryption Type: -
> Client Address: 192.168.125.202
> Failure Code: 0x12
> Logon GUID: -
> Transited Services: -
>
--------------------------------------------------------------------------------------------------------------------
>
> I continue to have my admin account locked out and I believe it is
> because of a service or program running under the old password, but
> can't determine which service, program or machine. Thanks,
> Tim
>



Posted by timpj5 on April 4, 2006, 1:00 pm
Please log in for more thread options
Yeah, I downloaded that but there isn't a whole lot of documentation.
I installed the dll to allow me to unlock per site, but it really isn't
that helpful.

As for our network, the domain\administrator account is the one being
locked out, but that account is also used to run certain services, ie.
BackupExec and each domain controller and/or server is also logged in
that way... I'm not saying that's a good policy to have, that's just
the reality. If I rename the admin account, I can expect these steps
if i'm not mistaken...

1) Change login account for dcs and member servers to the new account
name
2) Change all services that run under domain\administrator authority to
the domain\newadminname authority on all servers
3) Look for other workstations in event logs that run any
program/service as domain\administrator
4) ?? Any other reasonable steps that should be taken?

Question... will the name change automatically be recognized by AD as
far as permissions? will all directories that administrator currently
has access to automatically recognize the changed username? I'm
guessing that since AD only recognizes SID's as far as identification
(and changing the name doesn't change the SID), that would be the case,
but just making sure...


Similar ThreadsPosted
IP of machine locking account? March 13, 2008, 8:49 am
Account locking vs. logon types January 2, 2006, 8:03 am
Main Administrator account doesn't have Administrator groups right March 1, 2006, 2:35 pm
Administrator account July 6, 2007, 12:43 pm
Local Administrator Account April 17, 2007, 7:28 pm
Returning Administrator Account to 'default' - how to? September 12, 2005, 10:30 am
Local Administrator as service log on account January 11, 2006, 3:51 am
GPO not implementing rename of Administrator Account April 27, 2006, 5:19 am
Disable or rename administrator account September 1, 2006, 3:32 pm
Changing the Administrator account username for security? June 15, 2005, 10:20 am

Our other projects:

Art Dolls, Fairies and Mermaids - Sunnyfaces.net

Roy's Linux, Programming and Search Engines messages

1-Script XML SitemapXML Sitemap