Discussion in 'Windows Server' started by Barkingdog, Apr 22, 2008.

  1. Barkingdog

    Barkingdog Guest

    One of our users is running Win XP, Sp2 and intermittently getting this error
    in their System event log:

    Event ID: 40690
    Type: Warning
    Usre: N/A
    Source: LSASRV
    Category: SPNEGO (Negotiator)

    The Security System detected an attempted downgrade attack for server
    cifs/<servername>.<domainname>.net. The failure code from authentication
    protocol Kerberos was "The user account has been automatically locked because
    too many invalid logon attempts or password change attempts have been
    This happens while the user is logged on to their box so I think the
    description is not fully accurate. I also find that after a period of time (
    1 hour?) the problem seems to correct itself (i.e. disappear). She can now

    Any ideas how to fix this much appreciated.


    Barkingdog, Apr 22, 2008
  2. Whether the user is logged on or not, if another user or bot tries to log on
    using the user's username but failed for 5 times (default value), Account
    Lockout policy will block the user from logging on for 1 hour.
    Jabez Gan [MVP], Apr 23, 2008
  3. Barkingdog

    AllenM Guest

    Has the user recently changed her password? She probably was logged onto
    another machine when she changed her password. She must still be logged onto
    that other machine.
    AllenM, Apr 23, 2008
