none
LOCKED ACCOUNT ON MSFT-WIN-3/10.0.18362 RRS feed

  • Question

  • Hi everyone.

    After we start migration  to office365, manyf this users  started  to get his accounts locked  , what i have do:

    1. I have looked into domain servers logs and the source is an owa server.
    2. I looked into the iss owa server and i find the source ip and cs-agent is MSFT-WIN-3/10.0.18362.
    3. No old credentials on the user pc, no stored passwords on the browsers. ¿Any Ideas?

    Thanks in advance.



    Thursday, July 11, 2019 12:21 PM

Answers

  • Hi Daisy: Fortunately we found the source. If we take a closer look to the owa logs to the field cs-uri-query its tells me the source . So we are going to uninstall via GPO that app.


    Thanks for answering.


    • Marked as answer by Dsantiba Friday, July 12, 2019 2:08 PM
    Friday, July 12, 2019 2:00 PM

All replies

  • Hello,
    Thank you for posting in our TechNet forum.
    Does the event mentioned application/process information on OWA server?

    According to my knowledge, I will suggest you check outlook or other mail application on the client, mail application also could cause the issue.

    Also, please check the following article, I suppose the issue may occurred due to IIS token cache.
    https://docs.microsoft.com/en-us/previous-versions/windows/it-pro/windows-server-2003/cc773155(v=ws.10)#internet-information-services

    In addition, for troubleshooting account lockout issue in Exchange, I will suggest you create a new thread in Exchange forum to get more efficient support.

    Similar discussion for your reference:
    https://community.spiceworks.com/topic/384130-outlook-2010-causing-account-lockouts


    Tip: This answer contains the content of a third-party website. Microsoft makes no representations about the content of these websites. We provide this content only for your convenience.



    Best Regards,
    Daisy Zhou

    Please remember to mark the replies as answers if they help.
    If you have feedback for TechNet Subscriber Support, contact tnmff@microsoft.com.

    Friday, July 12, 2019 8:08 AM
    Moderator
  • Hi Daisy: Fortunately we found the source. If we take a closer look to the owa logs to the field cs-uri-query its tells me the source . So we are going to uninstall via GPO that app.


    Thanks for answering.


    • Marked as answer by Dsantiba Friday, July 12, 2019 2:08 PM
    Friday, July 12, 2019 2:00 PM
  • Hi,
    Thank you for your update and sharing. I’m very glad that the problem has been solved.
     
    As always, if there is any question in future, we warmly welcome you to post in this forum again. We are happy to assist you!

    Have a nice day!


     
    Best Regards,
    Daisy Zhou

    Please remember to mark the replies as answers if they help.
    If you have feedback for TechNet Subscriber Support, contact tnmff@microsoft.com.

    Monday, July 15, 2019 8:03 AM
    Moderator