Hi Gurus,
one of our Users is getting locked every day between 07:30-08:30. If we analyze the netlogon or security events on the DC we can see that the following event are registered.
4776,AUDIT FAILURE,Microsoft-Windows-Security-Auditing,Thu May 23 08:08:27 2013,No User,The computer attempted to validate the credentials for an account. Authentication Package: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0 Logon Account: ikesken Source Workstation: NETBIOS_HOSTNAME Error Code: 0xc0000234
05/24 08:11:19 [LOGON] VFTR: SamLogon: Transitive Network logon of VFTR\ikesken from NETBIOS_HOSTNAME (via NSI) Returns 0xC000006A
The problem is that there isn't any Workstation in our network named netbios_hostname. Does someone know how to find that workstation ? Any ideas or hints ?
I appreciate your help.
Kind regards,
Cengiz Kuskaya