Security-kerberos Event ID 14 . credential manager causes system to login to network with invalid password and lock the account.
A number of systems (about 100) on the domain keep locking a specific account. When this happens, the system logs event 14 which clearly shows the domain\account that is being used to access a server share. I have been able to clear the stored credential by logging in to a few systems using remote desktop and issuing the following commands: 1. Launch a command prompt and run "psexec -i -s -d cmd.exe" 2. From the new DOS window run "rundll32 keymgr.dll,KRShowKeyMgr" This launches the "Stored User Names and Passwords" dialog within the System context, which allows me to manually remove the stored credentials. Obviously, this manual process is extremely time consuming. What I'm looking for is a way to automate this procedure? Any help greatly appreciated. Thank you.
September 25th, 2012 12:52pm

Give a try to audit. You have not mentionet the history of error. This could not started from itself. Rgds Milos
Free Windows Admin Tool Kit Click here and download it now
September 26th, 2012 7:14pm

Hi, Based on my knowledge, it may be achieved via script. However, regarding how to create the script, it is recommended to post questions in Scripting Forums for better assistance. Thanks for your understanding. Hope this helps. Jeremy Wu TechNet Community Support
September 27th, 2012 2:51am

This topic is archived. No further replies will be accepted.

Other recent topics Other recent topics