Hi, We have created several new users recently and their accounts are all locking out. This happened after the weekend we updated out DC's to the latest patches.
Domain is 2008 R2 FFL and DFL.
All machines are Windows 7.
I have ran Eventcomb for the lockout events and the lockouts are coming from the machines themselves. Have tried re-creating their profiles but no luck. Also disabled all non essential scheduled tasks. We don't use a proxy so no authentication is required to access web. Have tried using TCPView but that doesn't log the data to a file so I cannot compare it to the DC event logs. Have managed to capture the data with wireshark but as of yet I have not been able to find the process through this.
Thanks for any help you can provide. Lets hope I have some hair left after this gets sorted! :)