Saturday, March 8, 2014

Microsoft Account Lockout Management Tools


AcctInfo.dll
The AcctInfo.dll tool provides information about a user's logon activities via an account information panel. The account information panel displays details that may help the administrator troubleshoot the cause of the lockout and includes details such as status of the lockout, password expiration dates and the last good and bad logon that the user experienced. The administrator may reset the user's password on the Active Directory using the AcctInfo.dll tool.
ALockout.dll
The ALockout.dll tool is placed on the user's PC after a lockout and is used to audit the user's log on and security logs. The administrator may use the Alockout.dll to determine applications that are causing frequent lockouts because of poor credentialing. Microsoft cautions administrators not to use the ALockout.dll tool on servers that host network applications or services. According to Microsoft administrators should also refrain from using ALockout.dll on Exchange servers, because the tool may prevent the Exchange store from starting.
AloInfo.exe
The ALoInfo.exe tool details user account name and password and the password's expiration date. The system administrator may use the ALoInfo.exe tool in combination with other account lockout tools to set tools, such as password change reminders which help reduce lockout events.
EnableKerbLog.vbs
Microsoft states that when EnableKerbLog.vbs is used as a startup script, Kerberos logs on to all client computers running Windows 2000 and later. Kerberos logging uses a three part authentication and synchronization process to allow clients to communicate with each other.
EventCombMt.exe
With the EventCombMt.exe, the administrator may gather client events such as system errors, warnings and failure and success audits from a group of clients. The information gathered may be exported to a single text file and can be used to analyze the log on and security activities of a group of clients.
LockoutStatus.exe
The LockoutStatus.exe can be executed at the command line or via GUI to display security and log on events for a locked out user. The information gathered is displayed in a comma-separated file which can be exported to a text file for later review.
NLParse.exe
The NLParse.exe tool filters the netlogon.exe information and may be used to extract information specific to lockouts. NLParse.exe saves time because the tool prevents the administrator from having to review many lines of event information. Information retrieved from the NLParse.exe may be exported to a text file.

1 comment:

  1. I read this blog it was really superb and excellent content I would like to say thanks to providing this for all of us. please share more content on msbi online training

    ReplyDelete