Posted on 12-09-2016 11:56 AM
Common problem: a user is getting locked out of Active Directory "mysteriously"
The challenge: a way to grep or find through the whole computer's log files to figure out whats been making requests recently.
so far I haven't been able to pull it off. something like
sudo grep -r -i kerb .
doesn't yield much. I think this is a universal challenge IT support faces and admins avoid. I assume there isn't a tool to help yet because no one is smart enough to make one, but hey, maybe one of us could?
Posted on 12-10-2016 12:02 AM
@j/k Are they on Sierra? Do they have iCloud enabled?
Posted on 12-11-2016 06:04 PM
@bentoms yes to both
Posted on 12-11-2016 06:39 PM
Sounds like the sierra failed auth problem:
https://www.jamf.com/jamf-nation/discussions/21320/sierra-ad-account-lockout-when-setting-up-icloud