• Some users have recently had their accounts hijacked. It seems that the now defunct EVGA forums might have compromised your password there and seems many are using the same PW here. We would suggest you UPDATE YOUR PASSWORD and TURN ON 2FA for your account here to further secure it. None of the compromised accounts had 2FA turned on.
    Once you have enabled 2FA, your account will be updated soon to show a badge, letting other members know that you use 2FA to protect your account. This should be beneficial for everyone that uses FSFT.

Windows accounts not locking

|-Goku-|

[H]ard|Gawd
2FA
Joined
Aug 24, 2003
Messages
1,762
We are having an issue where several of our domain controllers are not locking accounts after the threshold is hit for incorrect passwords.

We can see that the account has a "Last Bad Password" attempt, but the account never locks. We are also not showing any Account Lockouts on these DC's(Event ID 4740)

If we try locking ourselves at another site that uses a different domain controller, it locks as expected, and shows the proper event logging.

Has anyone else experienced this?
 
We are having an issue where several of our domain controllers are not locking accounts after the threshold is hit for incorrect passwords.
We can see that the account has a "Last Bad Password" attempt, but the account never locks. We are also not showing any Account Lockouts on these DC's(Event ID 4740)
If we try locking ourselves at another site that uses a different domain controller, it locks as expected, and shows the proper event logging.
Has anyone else experienced this?

No, but it potentially sounds like a difference between the security policies on the two DC's. I'd suggest checking them closely - both the domain level and the server level and compare the two. I suspect you'll find some obvious differences.
You could also run the Best Practise Analyser tool and compare the two - that might be a better option as if you've got one difference between them, it raises the question of what else is different... ?

2008: Best Practices Analyzer

2012: Run Best Practices Analyzer Scans and Manage Scan Results
 
No, but it potentially sounds like a difference between the security policies on the two DC's. I'd suggest checking them closely - both the domain level and the server level and compare the two. I suspect you'll find some obvious differences.
You could also run the Best Practise Analyser tool and compare the two - that might be a better option as if you've got one difference between them, it raises the question of what else is different... ?

2008: Best Practices Analyzer

2012: Run Best Practices Analyzer Scans and Manage Scan Results

Thanks Muz, I will check this out.
 
Back
Top