AD 帐户一直被锁定

AD 帐户一直被锁定

我们有一个 GPO,规定如果用户登录失败超过 3 次,则锁定该帐户 30 分钟。我们有一个用户一直被锁定,并且她的帐户下没有运行任何服务和计划任务。

审计日志

An account failed to log on.

Subject:
    Security ID:        NULL SID
    Account Name:       -
    Account Domain:     -
    Logon ID:       0x0

Logon Type:         3

Account For Which Logon Failed:
    Security ID:        NULL SID
    Account Name:       [email protected]
    Account Domain:     

Failure Information:
    Failure Reason:     Unknown user name or bad password.
    Status:         0xc000006d
    Sub Status:     0xc000006a

Process Information:
    Caller Process ID:  0x0
    Caller Process Name:    -

Network Information:
    Workstation Name:   Business-0005
    Source Network Address: 192.168.89.115
    Source Port:        52399

Detailed Authentication Information:
    Logon Process:      NtLmSsp 
    Authentication Package: NTLM
    Transited Services: -
    Package Name (NTLM only):   -
    Key Length:     0

This event is generated when a logon request fails. It is generated on the computer where access was attempted.

The Subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe.

The Logon Type field indicates the kind of logon that was requested. The most common types are 2 (interactive) and 3 (network).

The Process Information fields indicate which account and process on the system requested the logon.

The Network Information fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases.

The authentication information fields provide detailed information about this specific logon request.
    - Transited services indicate which intermediate services have participated in this logon request.
    - Package name indicates which sub-protocol was used among the NTLM protocols.
    - Key length indicates the length of the generated session key. This will be 0 if no session key was requested.

有任何想法吗?

答案1

发布的日志会为您提供一个 IP 地址。这可能是用户的机器、他们的手机或平板电脑,或者使用错误 ID 登录的另一个用户的机器。我经常发现是手机或平板电脑,用户更改了域密码,但没有更新他们的电子邮件应用程序,从而导致反复锁定。

这不是交互式登录,而是网络请求,因此用户可能会尝试远程验证并直接登录到计算机。很难说具体是什么服务,电子邮件是最常见的。

相关内容