I’ve recently added a 2000 member server to an NT4 domain. Users are mapping about 3 drives to this member server.
Suddenly it seems several people are getting their accounts locked out, first thing in the morning, or middle of the day in the midst of doing work.
I’ve been auditing successful and unsuccessful logins / logoffs, and I’m seeing typically User#1 logs in 3Xs (seems each drive mapping on this member server constitutes a seperate login), followed by 3Xs log off. And through out the day I see several folks being locked out, but I dont see what activity is leading to this.
These are Windows 98 clients. They have Norton Corporate v7.5 running on them, and I’ve wondered if start-up scans are contributing, but I dont see where the scan is scheduled to run with any particular user’s credentials. I did have a fella cover for me on vacation, last august and he had everyone in the domain change their password while I was gone.. I was seeing multiple log-ins (seperate log in for windows etc.), but I’ve had a helper delete the .pwl files and the users should all have a single long in now.
Anyone have some thoughts?