Windows 10: Domain users are locked

Discus and support Domain users are locked in AntiVirus, Firewalls and System Security to solve the problem; היי יש לי משתמשי דומיינים שנעולים לאחר שהם משנים את הסיסמה. איך בודקים מה נועל אותם? אין להם סיסמאות שמורות, רק לאחר מחיקת פרופיל זה יסתדר. תודה.... Discussion in 'AntiVirus, Firewalls and System Security' started by עין דורישי1, May 15, 2020.

  1. Domain users are locked


    היי

    יש לי משתמשי דומיינים שנעולים לאחר שהם משנים את הסיסמה.

    איך בודקים מה נועל אותם?

    אין להם סיסמאות שמורות, רק לאחר מחיקת פרופיל זה יסתדר.

    תודה.

    :)
     
    עין דורישי1, May 15, 2020
    #1
  2. changari Win User

    Raising the windows domain and forest issues?


    hi,

    I run a domain that was all 2003 r2 servers. I recently upgraded all my domain controllers to windows 2012 r2.
    That went off without any problems.. Our trust relationships had no issues also.

    My first step was to raise the Domain and Forest levels past 2003 to 2008. This went off without a hitch.
    These are the features for raising the levels to 2008:

    • Features and benefits include all default Active Directory features, all features from the Windows Server 2003 domain functional level, plus:
    • Read-Only Domain Controllers – Allows implementation of domain controllers that only host read-only copy of NTDS database.
    • Advanced Encryption Services – (AES 128 and 256) support for the Kerberos protocol.
    • Distributed File System Replication (DFSR) – Allows SYSVOL to replicate using DFSR instead of older File Replication Service (FRS). It provides more robust and detailed replication of SYSVOL contents.

    Forest Level Windows Server 2008

    • Features and benefits include all of the features that are available at the Windows Server 2003 forest functional level, but no additional features. All domains that are subsequently added to the forest will operate at the Windows Server 2008 domain functional level by default.


    My next step is to raise the domain and forest to 2008 r2, then 2012, and finally 2012 r2. I have been trying to find out exactly what I could expect from raising the Domain and Forest for each step.

    The step involving 2008 r2 seems relatively a non issue. But getting the couple of new features seem very nice

    Domain Level Windows Server 2008 R2

    • All default Active Directory features, all features from the Windows Server 2008 domain functional level, plus 2 new features

    Forest Level Windows Server 2008 R2

    • All of the features that are available at the Windows Server 2003 forest functional level, plus the following features:


    • Active Directory Recycle Bin, which provides the ability to restore deleted objects in their entirety while AD DS is running. <== New Feature very cool
    • All domains subsequently added to the forest will operate at the Windows Server 2008 R2 domain functional level by default.

    Here is my big concerns for the next raising of domain and forest to 2012.

    Forest Level Windows Server 2012:

    • All of the features that are available at the Windows Server 2008 R2 forest functional level, but no additional features.
    • All domains subsequently added to the forest will operate at the Windows Server 2012 domain functional level by default.

    Domain Level Windows Server 2012 R2: <=====
    Need to investigate more and why this post

    • DC-side protections for Protected Users. Protected Users authenticating to a Windows Server 2012 R2 domain can no longer:


    • Authenticate with NTLM authentication <==============(what issues may arise)
    • Use DES or RC4 cipher suites in Kerberos pre-authentication
    • Be delegated with unconstrained or constrained delegation
    • Renew user tickets (TGTs) beyond the initial 4-hour lifetime


    Will this affect my exchange anywhere users with remote access authenticating either clear of NTLM???
    and what would/may not to work properly day 1 when I raise the domain and forest to 2012. I cant really find anyone that can answer a straight question.

    Has anyone gone through this? what problems did you have, if any , if a lot???

    Any thoughts and suggestions will be much appreciated??

    thanks


    - - - Updated - - -

    One more point... I am not sure if I posted this to the correct forum.. So if I was wrong and it should be in a different one..
    PLEASE LET ME KNOW
     
    changari, May 15, 2020
    #2
  3. Gedpal Win User
    Domain Account Locked Daily


    Hello,
    I have similar problem. My domain account locks from time to time. I just upgraded from W8.1 to W10.
    I tried many steps to solve this but none is working.
    I found out some interesting things. Using a tool "Account Lockout Status" I found that Last Bad Pwd value is changed when I enter credentials after computer automatic or manaul screen lock out.
    I can work normally if I do not get a message about "Windows needs your current credentials":

    Domain users are locked [​IMG]

    If I get this message and do nothing - account very quickly locks out.
    If I do quick screen lock and unlock it will go ok for some time.
    Very strange. I replicate the problem of Last Bad Pwd value using another PC with W10. Some other users in domain are ok some same as mine.
    Something wrong with specific users and Windows 10 combination..




    Regards,
    Gediminas
     
    Gedpal, May 15, 2020
    #3
  4. Suriyana Win User

    Domain users are locked

    Domain joined windows 10 1703 keeps locking domain user account

    Hi

    I have a user on windows 10 1703. Windows will repeated ask for credentials and if he logs out and log in, his domain account will be locked. Earlier suggestion refers to kerberos but his AD account has no kerberos settings set. Please assist.

    Thank you and kind regards
     
    Suriyana, May 15, 2020
    #4
Thema:

Domain users are locked

Loading...
  1. Domain users are locked - Similar Threads - Domain users are

  2. Cached domain user

    in AntiVirus, Firewalls and System Security
    Cached domain user: Hello,We are currently facing an issue: we had a domain user with admin privileges, let's say "username123." This user account was disabled a few months ago. On all computers, the path C:/Users/username123 was changed to C:/Users/username123_old, and the registry key...
  3. Cached domain user

    in Windows 10 Gaming
    Cached domain user: Hello,We are currently facing an issue: we had a domain user with admin privileges, let's say "username123." This user account was disabled a few months ago. On all computers, the path C:/Users/username123 was changed to C:/Users/username123_old, and the registry key...
  4. Cached domain user

    in Windows 10 Software and Apps
    Cached domain user: Hello,We are currently facing an issue: we had a domain user with admin privileges, let's say "username123." This user account was disabled a few months ago. On all computers, the path C:/Users/username123 was changed to C:/Users/username123_old, and the registry key...
  5. Domain Locked Laptop

    in Windows 10 Gaming
    Domain Locked Laptop: I purchased a "refurbished" Dell 7420 from eBay.Worked perfectly until I installed Ubuntu Linux because I wanted to learn hands-on the OS.Now I am trying to revert back to Windows and did a full reset to do a clean install, and it gets to the "connect to network" but it does...
  6. Domain Locked Laptop

    in Windows 10 Software and Apps
    Domain Locked Laptop: I purchased a "refurbished" Dell 7420 from eBay.Worked perfectly until I installed Ubuntu Linux because I wanted to learn hands-on the OS.Now I am trying to revert back to Windows and did a full reset to do a clean install, and it gets to the "connect to network" but it does...
  7. Domain Locked Laptop

    in Windows 10 Installation and Upgrade
    Domain Locked Laptop: I purchased a "refurbished" Dell 7420 from eBay.Worked perfectly until I installed Ubuntu Linux because I wanted to learn hands-on the OS.Now I am trying to revert back to Windows and did a full reset to do a clean install, and it gets to the "connect to network" but it does...
  8. User@Domain / Domain\User problem

    in Windows 10 Ask Insider
    User@Domain / Domain\User problem: So I was checking my Windows 10 computer and saw that there was no domain, it was in a WORKGROUP. I needed to use the format "User@Domain" or "Domain\User" for something, and I do not know what to put. The username is just "User" and there is no password. submitted by...
  9. User@Domain problem

    in Windows Hello & Lockscreen
    User@Domain problem: So I was checking my Windows 10 computer and saw that there was no domain, it was in a WORKGROUP. I needed to use the format "User@Domain" or "Domain\User" for something, and I do not know what to put. The username is just "User" and there is no password....
  10. Domain users?

    in Windows 10 Installation and Upgrade
    Domain users?: Our company has about 40 Laptops that all have windows 7 on them. Since they are all connected to our domain the GWX app will not appear on any. Would running the upgrade from a WIN 10 DVD activate properly? 9968