Active Directory failed login attemps

bbennett 0 Reputation points
2023-02-02T16:52:40.79+00:00

I have a program that sends me an email with all of the login attempts be it a successful attempt or a failed login. I am seeing where after a user is able to authenticate against one of the domain controllers and logs into their workstation. I am seeing a failed login from a former employee's admin account. I am having a hard time tracking down what is causing this to happen.

Please help I am pulling my hair out.

Windows for business | Windows Client for IT Pros | Directory services | Active Directory
0 comments No comments
{count} votes

3 answers

Sort by: Most helpful
  1. Rafael da Rocha 5,251 Reputation points
    2023-02-02T17:26:38.4833333+00:00

    Hello,

    this is probably a service or scheduled task configured to run under that user credentials.

    0 comments No comments

  2. Thameur-BOURBITA 36,261 Reputation points Moderator
    2023-02-02T23:25:30.79+00:00

    Hi @BBennett

    In the event check the IP of source machine. If you are able to identify this machine , check if there is mapped drive, scheduled task, windows service, script still using the admin account.

    Please don't forget to mark helpful answer as accepted

    0 comments No comments

  3. Limitless Technology 44,766 Reputation points
    2023-02-03T17:12:22.9233333+00:00

    Hi. Thank you for your question and reaching out. I’d be more than happy to help you with your query.

    To track down the cause of the failed login attempts from a former employee's admin account, you can try the following steps:

    1. Check Event Viewer on the domain controller and workstation where the login attempts are recorded to see if there are any specific error messages or codes related to the failed login attempts.
    2. Monitor the security logs of the domain controllers and workstations for any suspicious activity.
    3. Check if there are any scheduled tasks or scripts that are running under the former employee's admin account.
    4. Verify if there are any devices or systems that may be authenticating with the former employee's admin account credentials, such as automated backup systems or network printers.
    5. If the issue persists, you can use network monitoring tools to track the source of the failed login attempts.
    6. If you are still unable to find the cause of the failed login attempts, you may need to change the password for the former employee's admin account to prevent further unauthorized access.

    It's important to take the necessary steps to secure your network and prevent unauthorized access. It is recommended to engage the services of an experienced IT security professional if you are unable to resolve the issue.

    If the reply was helpful, please don’t forget to upvote or accept as answer, thank you.

    0 comments No comments

Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.