Skip to main content
Question

iMac causing AD account to Lock everyday.

  • December 18, 2018
  • 4 replies
  • 15 views

Forum|alt.badge.img+3

Hi all, we are experiencing issues with some Active Directory accounts locking when they come to log into the machine their account is locked. Just for a bit of content our iMacs have DeepFreeze enabled on them so the rules out keychain and they also reboot every night. Any suggestions would be greatly appreciated.

4 replies

AVmcclint
Forum|alt.badge.img+21
  • Esteemed Contributor
  • December 18, 2018

If the user's home folder is included in the freeze, then it's possible that the passwords stored in the frozen keychain could be sending old credentials.


Forum|alt.badge.img+3
  • Author
  • New Contributor
  • December 18, 2018

The Macs are Frozen in a Blank state with no user profiles so when the user logs in it will create an account for them until it is restarted which is done on a schedule every night.


Forum|alt.badge.img+15
  • Valued Contributor
  • December 18, 2018

Do you have a reason to suspect it's the iMac itself that's causing the lockouts? If you have a tool like AD Audit (or others) you can determine the device or IP where the lockout is occuring. Are the users setting up email or other services on phone or other devices that might be causing the lockout?


Forum|alt.badge.img+3
  • Author
  • New Contributor
  • December 18, 2018

We suspect this due to running a script that can find were the account is locked out from. Users are not able to attach their account to any mobile device due to security. When we run the script with a windows machine it will display the hostname. However with a iMac it does not show anything. Some of the accounts that are reporting this issue and newly set up accounts