I have a domain account which keeps getting locked without any prior wrong password login attempts:
I.e (completely stripped off the details, just to give you an idea)
10:15:49 - logon successful 10:16:55 - logon failed (account locked)
There's something very odd here: I would expect at least one event between a successful logon and failed logon due to locked password. Where's the event that causes the lock with a failed password?
Other information:
-It's a MS RemoteApp system: there's a remoteapp system where people login via a web portal. The authentication happens during people logging into the web portal.
-There's no genius who's randomly locking accounts, even that should be in the logs, amirite?