The Account Lockout Examiner service account

Rights and permissions required for the Account Lockout Examiner service account. If you do not want to grant the service account a domian admin
Email It to Me Print this Page
If you do not want to grant domain admin rights to the service account, you can create a less priviledged one. To create an account which has all required rights please perfrom the following steps. 

On any Domain Controller that has Group policy management:

Step 1. Enable Manage auditing and security log user rights for this account: 
  1. Run Group Policy Management 
  2. Navigate to the Group Policy Object which is applied to all Domain Controllers (Default Domain Controllers Policy, for example)
  3. Right click on it and select Edit
  4. Expand Computer Configuration -> Windows Settings -> Security Settings -> Local Policies -> User Rights Assignment 
  5. Double click on the Manage auditing and security log policy
  6. Click Add user or group, specify the Account Lockout Examiner service account and click OK

User-added image

Step 2. Add the service account to the required security groups
  1. Run Active Directory Users and Computers
  2. Expand <Domain name> - Built-in
  3. Click the Account Operators group and select Properties
  4. Go to the Members tab and add the user account you want to use for the Account Lockout Examiner service to the list.
  5. For Windows 2008 and above Domain Controllers, one additional step is required:  Add the service account to the Event Log Readers group.

User-added image

On every monitored Domain Controller:

Step 3. Enable WMI access
  1. Run Computer managemnet (Start->Administrative Tools->Computer Management)
  2. Expand Services and Applications -> WMI Control.
  3. Right-click on it and select Properties.
  4. Go to the Security tab and expand Root -> CIMV2.
  5. Highlight CIMV2 and click the Security button at the bottom of the window.
  6. Add the user account you want to use for the Account Lockout Examiner service to the list
  7. Grant it with Remote Enable permission (put a check in the Allow checkbox). 

User-added image


Step 4. Configure DCOM settings
  1. Open Component Services (Start -> Programs -> Administrative Tools -> Component Services).
  2. Navigate to Component Services - Computers - My Computer. Right click it and select Properties
  3. Go to the COM Security tab.
  4. Click the Edit Limits button in the Launch and Activation Permissions group box.
  5. Add the user account you want to use for the Account Lockout Examiner service to the top window.
  6. Set Allow checbox for the Remote Activation option.

User-added image

NOTE: steps 3 and 4 might require a reboot to apply new settings

On the machine where NetWrix Account Lockout Examiner is installed:

Step 5. Grant local administrator rights to the service account.

  1. Run Computer management
  2. Expand System tools - Local users and groups - Groups
  3. Right click Administrators group and select Add to group
  4. Clcik Add and specify the service account. Click Ok

User-added image


On all machines that need to be examined by Account Lockout Exmainer:

Step 6: Grant the local administrator rights to the service account.

This can be done manually or by means of Group policy. Local admin rights are also necessary to find the root proocess causing invalid logons.
 
Was this information helpful?