question

cornenietnodig-5642 avatar image
0 Votes"
cornenietnodig-5642 asked FanFan-MSFT commented

AD user Guest keeps beeing locked out

ad guest user keeps being locked out from different sources. The strange thing here is that the sources from where the guest is beiing locked out does not excists...
i cannot ping the ip or the name of the source which is in evenid 4740 in the domain controller security log.

The guest account is beiing locked from different sources which i cannot control / vieuw because they do not excist.

Someone an idea?

What i have already done:
rename the guest account in AD
password never expired off and later on
user cannot change password off and on
disabled the guest account
the guest account has no password set. I have tried to set the password but do not think this has eny effect because of the password policy..

windows-active-directory
5 |1600 characters needed characters left characters exceeded

Up to 10 attachments (including images) can be used with a maximum of 3.0 MiB each and 30.0 MiB total.

Thameur-BOURBITA avatar image
0 Votes"
Thameur-BOURBITA answered

Hi,

You should check the IP , checking the ping is not enough to confirm that this IP doesn't exist. May be the ping is blocked by firewall.

Please don't forget to mark helpful reply as answer

5 |1600 characters needed characters left characters exceeded

Up to 10 attachments (including images) can be used with a maximum of 3.0 MiB each and 30.0 MiB total.

cornenietnodig-5642 avatar image
0 Votes"
cornenietnodig-5642 answered

Hi, this is not likely that the ip is blocked by a firewall, i have also tried the ip. The source pcnumbers does not excist anymore in AD. I have deleted the dns record from the source in dns, but it the lockouts keeps coming for the guest account.

5 |1600 characters needed characters left characters exceeded

Up to 10 attachments (including images) can be used with a maximum of 3.0 MiB each and 30.0 MiB total.

FanFan-MSFT avatar image
0 Votes"
FanFan-MSFT answered

Hi,

Based on understanding, the caller computer in the event 4740 existed before, but deleted from AD, right?
Except the DNS records, you can also make sure the client was deleted from the ADUC and the ADSI.
I would also recommend you check the DC status and the replication between DCs.
You can do this by the command:
Dcdiag /v >c:\dcdiag1.log
Repadmin /showrepl >C:\repl.txt
Repadmin /showreps * 

If there are any errors in the output, you may try to fix the error firstly.
Best Regards,

5 |1600 characters needed characters left characters exceeded

Up to 10 attachments (including images) can be used with a maximum of 3.0 MiB each and 30.0 MiB total.

cornenietnodig-5642 avatar image
0 Votes"
cornenietnodig-5642 answered

Dcdiag /v >c:\dcdiag1.log
Repadmin /showrepl >C:\repl.txt

Where successfull, no errors.

The latter gives an error: LDAP error 81.

I must google this one..

5 |1600 characters needed characters left characters exceeded

Up to 10 attachments (including images) can be used with a maximum of 3.0 MiB each and 30.0 MiB total.

FanFan-MSFT avatar image
0 Votes"
FanFan-MSFT answered FanFan-MSFT commented

How may DCs do you have? Every DC works well by the command: Dcdiag /v >c:\dcdiag1.log, right?
Are there any Old DCs that no longer exist in real life, but exist in AD?

Confirm Ports for LDAP: https://social.technet.microsoft.com/wiki/contents/articles/584.active-directory-replication-over-firewalls.aspx

Best Regards,

· 3
5 |1600 characters needed characters left characters exceeded

Up to 10 attachments (including images) can be used with a maximum of 3.0 MiB each and 30.0 MiB total.

Hi,
Welcome to share your current situation if there are any updates.
Please feel free to let us know if you need further assistance.
 
Best Regards,

0 Votes 0 ·

Hi FanFan,

dcdiag1.log gives me 3 errors but it looks like errors with desktops in the field.

i see old DC's from an other domain which are still excists but there is not trust anymore..


0 Votes 0 ·

Hi,
Are there any event logs related on the DCs?
Fan

0 Votes 0 ·
cornenietnodig-5642 avatar image
0 Votes"
cornenietnodig-5642 answered FanFan-MSFT commented

Yes we have 1 domain controller with syncing problems, we look into that and see if that is the cause of this..

· 1
5 |1600 characters needed characters left characters exceeded

Up to 10 attachments (including images) can be used with a maximum of 3.0 MiB each and 30.0 MiB total.

Hi,
Welcome to share your current situation if there are any updates.
Please feel free to let us know if you need further assistance.
 
Best Regards,

0 Votes 0 ·