Tek-Tips is the largest IT community on the Internet today!

Members share and learn making Tek-Tips Forums the best source of peer-reviewed technical information on the Internet!

  • Congratulations bkrike on being selected by the Tek-Tips community for having the most helpful posts in the forums last week. Way to Go!

User Account locks out AFTER they log in.

Status
Not open for further replies.

DocHolden

MIS
Jun 25, 2002
48
US
We are running AD and I have a user who's account locks after they log into thier computer. She can not access any of the mapped drives. When I check her account in AD it is locked. If I unlock it and she tries to access a mapped drive the account locks. No software or hardware have been added to her computer and her's is the only one doing it. I have found if I go into safe mode and delete her usrclass.dat file then she is good for a while and then it happens again. The file is located at "C:\Documents and Settings\"user name"\Local Settings\Application Data\Microsoft\Windows"

Any help will be great.
 
This usually happens when this someone changed their password and are currently logged in another machine(s). Check the "Sessions" and "Open Files" on your File Server and see if this user is logged in anywhere else besides the computer your trying this person with or look at the security logs (if enabled) to see any Failed logon attempt. The failed logon attempts usually give from which computer. Log them off and the lockout problems should go away.



"In space, nobody can hear you click..."
 
This was not the problem. She is only logged into her computer and no password change has been done for at least 3 weeks.
 
Several things can cause this, but here's the most common:

1. Bad NIC on client machine - I know it's odd, but in my experience this is the most likely cause.

2. System time not correct - Kerberos is very time sensitive. If the clocks dont match within certain parameters, Kerberos will error and the server sees failed login attempts. This can hapen within a few minutes of logging in.


MCSE CCNA CCDA
 
Also services that start with user credientials.. Check all the services on the machine and make sure they are set to Local System or an non-expiring user account.

Mike
 
Status
Not open for further replies.

Part and Inventory Search

Sponsor

Back
Top