User Account Lockout

Luca Buratti 1 Reputation point
2021-03-19T10:25:11.25+00:00

I've got many user's lockout my limit is 20 bad password As you can see in the picture the event 4776 is present many times in the same minute it can't be an user attempt. Netlogon log are registering the pid but it is not possible catch it in the destination computer , the process associated is gone after the bad password event. Moreover on the client machine there is not in security event the error replicated i've done the same conclusions of Mr. Joe Alves here https://social.technet.microsoft.com/Forums/en-US/64c744f7-265c-46d4-a59e-35bafc17e3fd/kerberos-preauth-lockouts?forum=winserversecurity But I don't understand what it means whe he says "To fix it I created a normal domain account and used that on both servers." there is a particular procedure to follow? my accounts are all created with Active Direcry User and Computer ... Thank you Luca ![79631-image.png][1] [1]: /api/attachments/79631-image.png?platform=QnA

Active Directory
Active Directory
A set of directory-based technologies included in Windows Server.
5,983 questions
0 comments No comments
{count} votes

6 answers

Sort by: Most helpful
  1. Luca Buratti 1 Reputation point
    2021-03-29T07:30:55.843+00:00

    So now I'm in a dead end.
    If DisableDomainCreds is active the actual credentials are not cashed so it means that if the laptop's user is at home he cannot login to his computer also if CachedLogonsCount is set to 100!

    0 comments No comments