
Options
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
‎03-30-2020 08:21 PM
A couple of weeks ago, it seems like we had a hacking attempt. We changed all passwords and set a group policy for locking user accounts after x attempts.
Unfortunately we had an admin account keep getting locked which killed services that used that account. I have changed the services to new accounts and the admin account, every so often gets locked.
Is there a report to find what workstation/server is doing the failed login attempts and locking the account?
Thanks
Joe
Unfortunately we had an admin account keep getting locked which killed services that used that account. I have changed the services to new accounts and the admin account, every so often gets locked.
Is there a report to find what workstation/server is doing the failed login attempts and locking the account?
Thanks
Joe
Labels:
- Labels:
-
General Discussion
1 REPLY 1

Options
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
‎03-31-2020 01:19 AM
Not in Lansweeper. This is an Event Log / Login Server Issue.
Check out the event logs on the machine for the lock / failed login. That should give you the IP address of the machine or Domain Controller. Then check that DC for the lockout attempts and that should give you the originating machine.
Check out the event logs on the machine for the lock / failed login. That should give you the IP address of the machine or Domain Controller. Then check that DC for the lockout attempts and that should give you the originating machine.
