Hi,
I have an user account which locks out almost everyday in AD & Security logs from Domain Controller indicates the caller computer name is the exchange server. When I look into the exchange server Security Logs I can see there are multiple failed logins but it gives me no specific info about from where is this originating from.
I've checked the IIS logs as well but can't find anything related related to this particular user account (tempuser).
Also checked for any Active Sync devices using (get-activesyncdevicestatistics) but comes up empty.
Is there any way that I can find the culprit?
(Previously I've posted this question on Windows Server Security section & I was asked to check on this form for any augestions)
Exchange Server Log:
Event ID (4625)
Event ID (4776)
The computer attempted to validate the credentials for an account.
Authentication Package: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0
Logon Account: tempuser
Source Workstation: MyExchangeServer
Error Code: 0xc0000064
Many Thanks in advance,
Asiri