Site Overlay

Persistent user account lockout

Repeated lockout of a user account in Active Directory can occur for the following reasons.

  • Mapped Network Shares
  • Shortcuts that work with RunAs
  • Accounts defined as Service Account
  • The account used for the Schedule Task
  • Accounts defined for processes running on different servers, computers, or applications
  • Centralized programs that perform user authentication or verification (AD authentication, or application-layer control, etc.)
  • Accounts used on mobile devices that work with Activesync
  • A malicious software infection of a user's computer

Thanks to the LockoutStatus software released by Microsoft, you can detect locked accounts. You can download the software here https://www.microsoft.com/en-us/download/details.aspx?id=18465

image 13
Persistent user account lockout

ad account lockout