1.8 KiB
OVERVIEW
Account lockout status, including where the account was locked out is now available through ADEX reports.
PROCEEDURE
Once you login to ADEX, the reports are within Reports | Maintenance | User Maintenance. Use the pull-down and select User Account Locked. Enter the user's hash (preferred) or other identifying information like their last name. Click Get Info to retrieve details to include the location where the account lockout occurred.
TROUBLESHOOTING
In most cases chronic lockouts are occurring because one of the following occurred after the user changed their password:
1. Users making use of Windows 7 feature Fast Windows Switching where multiple users are logged onto a workstation at the same time (Windows keeps other sessions dormant). The affected user doesn't remember that they were logged onto a workstation elsewhere.
Resolution: Reboot the workstation(s) where the lockout is occurring.
2. A user maps a drive letter to a share and selects the option to restore connections on logon.
Resolution: delete all mapped drives and restart. To delete all mapped drives, have the user type the following from a command prompt and then restart: **net use /del ***
3. User incorrectly types their username/password 3 times within 20 minutes.
Resolution: Remember password to avoid lockout events.
4. A password is outdated in the Credentials Stored in Credential Manager (Control Panel\User Accounts\Credential Manager)
Resolution: Edit or Remove the Credentials.
Related: Report data originates from Quest: Quest Change Auditor