Enable Change Notification On All Site Links on an Windows 2003 AD is not working for account lockout
our configuration domain 5 different sites 5 domain controllers. clients on sites logged in automatically basic user. user can log in own credentials via secundary logon. possible make remote desktop connection other site.
for security reasons introduced account lockout policy. default lock out active on site lock out done. have enabled change notification on site links. lock out active @ site lock out done , site pdc role active. other sites give message of lock out when user give wrong password. if user give right password user can log in on site.
is there solution block login?
password reset,account lockout events are replicated between dc's.
reason if administrator resets password user has forgotten password, change replicated pdce(same account lockout). isn’t situation pdce notified change instead change pushed it. reason important if user attempts logon , password attempt use fails, dc send hash password (password never sent on wire) pdce check see if password correct, since there latency in replication.
i recommend first check health of dc.this due replication issue between dc(due dns misconfig,necessary port not open ad replication,etc).
run dcdiag /q and repadmin /replsum to check health of dc.
i there no issue between dc can configure change notification.
change notification within site , between site refer below link
http://technet.microsoft.com/en-us/library/cc961787.aspx
http://support.microsoft.com/kb/232690
http://blogs.technet.com/b/kenstcyr/archive/2008/07/05/understanding-urgent-replication.aspx
password replication policy rodc.
http://technet.microsoft.com/en-us/library/cc730883(ws.10).aspx
hope helps
best regards,
sandesh dubey.
mcse|mcsa:messaging|mcts|mcitp:enterprise adminitrator | blog
disclaimer: posting provided "as is" no warranties or guarantees , , confers no rights.
Windows Server > Directory Services
Comments
Post a Comment