VMware Cloud Community
SandyB
Enthusiast
Enthusiast

Domain Admin account lock out attempts coming from Virtual Center???

We changed our Domain Admin password a few days ago and now on our new Netcrunch monitoring platform we are being spammed by messages saying the domain Administrator account is being locked out from our Virtual Center server....

there are no scheduled tasks or services that run using this account and i cant find anywhere within the Virtual Center application that would hold these credentials.

does anyone have any ideas? :_|

0 Kudos
29 Replies
bulletprooffool
Champion
Champion

SandyB, check 2 things:

1) Verify that no servives are running on the host, under the context of the domainadmin - if any are, this should be changed to use a different user account, to prevent this kind of thing happening (create a dedicated Service account)

2) Check that your DB does not use Domain admin for access.

Good luck - please post back with your resolution

Incidetally, Microsoft has a tool called EventCombMT that will allow you to query your DCs / event logs for event lockout events

One day I will virtualise myself . . .
0 Kudos
SciMike
Contributor
Contributor

I have looked though these posts and I still can't figure out why the domain admin account keeps getting logged out. I have done a repair to the Update Manager on Virtual Center and none of the services use the domain admin account.

I don't believe I have any Virtual Center appliances installed. How could I check that? Also, is there any way to determine what could be sending stale credentials the VMware VirtualCenter Server service? As stated by someone else, when I stop the service the account lockout issue goes away

0 Kudos
Vikanich
Contributor
Contributor

Hi everyone! I had the same issue after my password change.

It was because of VMware Data Recovery connect account.

0 Kudos
SciMike
Contributor
Contributor

I don't have one of those, so thats one thing it can't be :D. This is drivng me crazy though, I have no clue where to go from here.

0 Kudos
SciMike
Contributor
Contributor

I have an update to my situation. I have looked into it a bit further using a packet sniffer on my Virtual Center server. Right before I see the username being used (with a stale password) I have noticed there is talk b/c the virtual center server and the virtual host server. It is SSL encrypted so I can't verify that the credentails are coming from the virtual host, but I'm extremely sure since it is the only address in the timeframe where the virtual center sends the authentication request to the domain controller.

If virtual center is getting the information from virtual host, how can I traceback from the virtual host?

0 Kudos
EsVau
Contributor
Contributor

Hi Everyone,

old Thread I know - but still a topic. I had the same problem yesterday.

You have to check the extension you've installed to vcenter. In my case the "Netapp-Virtual Storage Console" was the trigger.

http://kb.vmware.com/selfservice/microsites/search.do?language=en_US&cmd=displayKC&externalId=200170...

0 Kudos
CHCNOC
Contributor
Contributor

Solved.

Check if you have Veeam monitor installed.

If you do try stopping the Veeam Data Collector Service and see if the failures audits go away. If they do then change the login account credentials this service uses as appropriate. This resolved the issue for us after days of running into brick walls.

0 Kudos
CHCNOC
Contributor
Contributor

Solved.

Check if you have Veeam monitor installed.

If you do try stopping the Veeam Data Collector Service and see if the failures audits go away. If they do then change the login account credentials this service uses as appropriate. This resolved the issue for us after days of running into brick walls.

0 Kudos
mfonnegra
Contributor
Contributor

After hours of research and doing everything you told me guys, I resolved my problem in my case the problem was the netapp virtual plugin that store the password and the username (domain admin user of the AD) to check the status of the Netapp Box and the Luns, the only thing that that I did was to update the password and now everything is working.

Reference page (http://itblogit.com/2011/04/account-lockout-vpxd-exe/)

Thank you very much to all of you for your posts and support.

Mauricio Fonnegra System Enginner
0 Kudos
bobby311
Enthusiast
Enthusiast

Had the exact same issue, battled it for 3 days, annoyed the hell out of my co-workers because I had to ask them to unlock me every 10 minutes

Turns out that I used my domain account for NetApp Snap Protect software. In the configuration of SnapProtect my creds were used to connect to vCenter.

SnapProtect was installed on another server in my environment. vpxd logs did not log the server name nor did netstat show the IP for the connection

Hope this helps someone!

moral of the story - don't use your domain account and use a SERVICE ACCOUNT and never change the password! Smiley Happy

0 Kudos