Howdie!
kingkong1977 schrieb:
> User AD account getting frequently. We run a report on domain control
> log using eventcombo.exe bad request is coming from his work station. we
> checked mapped network drives other services, we are unable to find what
> causing account lock out. There is any way we can find what services is
> trying to login and failing in system.
Since you already have identified that the lockout is coming from the
user's workstation, I'd probably simply go capture a network trace on
the problematic machine and then wait for it to lock the account and
then come back and analyze the capture's output.
Cheers,
Florian
--
Microsoft MVP - Group Policy
eMail: prename [at] frickelsoft [dot] net.
blog:
http://www.frickelsoft.net/blog.
ANY advice you get on the Newsgroups should be tested thoroughly in your
lab.