Account lockout and management tools
Sometimes, when you get a call regarding a password reset, you can already guess who it's from. Most organizations have one—that one employee who somehow manages to forget their password and gets locked out of their account more than everyone else. So you reset this forgetful user's password, and sure enough, five minutes later they call back saying they're locked out again. Only this time it's because the password wasn't updated in the many places they use it, like active user sessions, mapped network drives, etc. Manually sifting through the long list of applications and processes to find and replace stale credentials could easily take a few hours, hampering the productivity of both the forgetful user and the help desk technician."30% of help desk queries are related to password reset management and account lockouts."
-Gartner-
Account lockout policies are designed to limit brute force attacks, which try to break into accounts by guessing multiple different passwords one after the other. However, getting the balance right with the account lockout threshold (the number of attempts before an account is locked out) and the account lockout duration (the amount of time an account stays locked out) can be tricky as each organization operates uniquely. Microsoft offers a number of recommendations to determine the optimum password policy settings, but these recommendations alone aren't enough. Below is a list of Microsoft's tools that assist IT technicians in determining the source of account lockouts.- AcctInfo.dll
- ALockout.dll
- ALoInfo.exe
- EnableKerbLog.vbs
- EventCombMT.exe
- LockoutStatus.exe
- NLParse.exe
Try ADAudit Plus to seamlessly find and resolve locked out user accounts.30-days FREE trial!