Why Active Directory account gets repeatedly locked when polling AD resources?
Q: When I monitor Active Directory resources, account used periodically gets locked. Why this is happening and how to avoid that?
A: Active Directory (domain) is often configured to lock the account after several unsuccessful login attempts. Most probable reason for account lockup is its changed password. If password has been modified at Active Directory (domain), but change had not been applied in monitor settings, account might get locked after several polling attempts.
Note: it is strongly recommended to create least privileged AD account to be used in monitoring. That’s better from both maintenance efforts and security point of view.
Related Topics:
How can IPNetwork Monitor help me for server performance tuning?
How could all the important data be gathered to set up Windows Server monitoring?
Check out our Knowledge Base where we answer questions regarding various topics. The account can be locked after repeated failed logins, commonly because its password changed in Active Directory but the monitor settings still use the old password. Update the credentials used by the monitors whenever the account password changes, and verify that all AD resource checks use the current password. Use a least privileged Active Directory account dedicated to monitoring to reduce maintenance effort and improve security.
Frequently Asked Questions
Why can an Active Directory monitoring account become locked?
How can repeated AD account lockouts be prevented?
What kind of account should be used for AD monitoring?