cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
jarchibald
Engaged Sweeper
A couple of weeks ago, it seems like we had a hacking attempt. We changed all passwords and set a group policy for locking user accounts after x attempts.

Unfortunately we had an admin account keep getting locked which killed services that used that account. I have changed the services to new accounts and the admin account, every so often gets locked.

Is there a report to find what workstation/server is doing the failed login attempts and locking the account?


Thanks

Joe
1 REPLY 1
CyberCitizen
Honored Sweeper
Not in Lansweeper. This is an Event Log / Login Server Issue.

Check out the event logs on the machine for the lock / failed login. That should give you the IP address of the machine or Domain Controller. Then check that DC for the lockout attempts and that should give you the originating machine.