Network Management
Account gets locked out of Active Directory in the SolarWinds Platform
This article can help when an account gets locked out of AD and customer calls in wants to check if NPM is the cause.
First published date
Last published date
Overview
Account gets locked out of AD
This is a very common issue. A customer calls in and says that his/her AD account gets locked out and they want to identify if NPM is the culprit.
Product section
Cause
Resolution
- Check the database manager and query the Credentials table
Here you’ll see a list of account, find the account and check the credential owner column. On this example “administrator” is being used by APM which is SAM.
On a customer environment you’ll find a lot of names here. If the account is being used by the SolarWinds Platform you can find that in the Manage your credential field and change it there.
Settings > Credentials > Manage Window credentials
Now if it’s SAM, you’ll find it in the SAM credentials library on
SAM Settings > Global SAM Settings > Credential Library
You can also find it on Orion Report scheduler. Just edit the schedule and go through the advanced settings
Now, that you’ve searched every hiding place that those credentials might be in the SolarWinds Platform then, it may lead to an environmental issue with the customer. Meaning that the issue is on their end.
Notes:
Each module installed in NPM may or may not have credentials settings. UDT has one for example, just go through those pages but always reference it with the credential table.
You can also check these (2) reports which should show you Credentials being used by WMI Nodes (at the NPM level) and what's being used at the APM/SAM level
CREDENTIALS USED BY WMI NODES
https://thwack.solarwinds.com/docs/DOC-172320
CREDENTIALS USED BY APM COMPONENT MONITORS
https://thwack.solarwinds.com/docs/DOC-160488
To use these download the .OrionReport and then copy them into this path on your Orion/NPM Server
--> C:\Program Files (x86)\SolarWinds\Orion\Reports\
Then go back to your SolarWinds Platform Web Console > http://<orionservername>/Orion/Reports/Default.aspx
Then search for the word "Credentials" and you should find both:
CREDENTIALS USED BY WMI NODES
CREDENTIALS USED BY APM COMPONENT MONITORS
Then put a check mark next to the one you want to view and then click > VIEW REPORT
Your output should look like these:
- Need to determine for any old remnants of admin accounts that are no longer being used; have it deleted permanently
Please note that Thwack is a community space where users may post any content as a suggestion or recommendations to you for your internal use. The information set forth herein may come from third-party websites or customers. SolarWinds is not liable for any downtime or any issue that may occur if you perform the following suggestions on the link provided. Your organization should internally review and assess to what extent, if any, such custom scripts or recommendations will be incorporated into your environment