Hi @KuchJ ,
Greeting! Hope everything is fine with you.
After discussing with our Active Directory Domain Service engineer, we think tracing and monitoring should be necessary if the account is in Active Directory and still an active user.
You can capture network traffics by Network Monitor when the issue reproduced on problematic device . Please download the “Network Monitor” as below link in advance and install as Administrator on problematic node and :
https://www.microsoft.com/en-sg/download/details.aspx?id=4865
However, Please understand analysis of network traffic is beyond our forum support level. So I would suggest you contact Microsoft Customer Support and Services where more in-depth investigation can be done so that you would get a more satisfying explanation and solution to this issue.
You may find phone number for your region accordingly from the link below:
Global Customer Service phone numbers
Best Regards,
Sunny
----------
If the Answer is helpful, please click "Accept Answer" and upvote it.
Note: Please follow the steps in our documentation to enable e-mail notifications if you want to receive the related email notification for this thread.
Thanks for your feedback. Will wait for your good news!
Finally was able to connect on his laptop and try that out around 10:30. Looks like it is still going which i am surprised. Not sure what might be doing it. It is a super clean system but obviously something is trying to do something. Here is a picture of it. Thank you again for trying to help me.
![49228-image.png][2]
Hi,
Thanks for your feedback.
May I know if there is related Event logs in Event viewer when the issue occurred? If yes, please provide screenshot for further troubleshooting.
Best Regards,
Sunny
Hello Sunny,
Still amazes me his account doesn't lock out at all but this is the only error his account and it is random on one of the three domain controllers. Here are the event logs from the main domain controller. Thank you again for your help!
Hi @KuchJ ,
Thank you very much for your feedback.
The result code 0X6 of Event 4768 means "The username doesn’t exist." Please kindly check if the account jsayersmith was existed in ADUC. Or may I know whether this account was a service account?
Best Regards,
Sunny
Greetings Sunny,
The account is in Active Directory and still an active user. Odd that that the error is for a user doesn't exist but he can login to the VPN and Office 365 with zero issues. Never locks out or anything and triple check his credential manager again and super clean. Had to get that one strange issue I guess. :P
Sign in to comment
@Sunny Qi
I will give that a shot with the Network Monitor tool. Thank you for all your help. Really appreciate it big time. :)
Hi @KuchJ , it's my pleasure to help you! Please help to accept the useful reply as answer if you want to end this thread up as it's important to me.
Thank you for the reminder @Sunny Qi . Thank you again for your help and Happy Holidays!
You're welcome! Happy holiday~
Sign in to comment
Hello @KuchJ ,
Did you identified the root cause of this issue? what was it?
Sign in to comment
I am also curious to see if anyone found a resolution for this as I have those exact security settings in our domain per NIST requirements and I am seeing the same thing for a local admin account on newly created workstations that are added to our domain.
Sign in to comment
Activity