Event / log entry corresponding to the "Last Bad Pwd" time in Lockoutstatus.exe
hi
these possibilies lockout issue,
-mapped network drives
-logon scripts map network drives
-runas shortcuts
-accounts used service account logons
-processes on client computers
-programs may pass user credentials centralized network program or middle-tier application layer
-active sync devices (cell phone,etc..)
i can see source machine listed >>>> check process monitör identify source process; https://technet.microsoft.com/en-us/sysinternals/processmonitor.aspx
this posting provided no warranties or guarantees,and confers no rights. best regards burak uğur
Windows Server > Directory Services
Comments
Post a Comment