Network Management

Account gets locked out of Active Directory in the SolarWinds Platform

This article can help when an account gets locked out of AD and customer calls in wants to check if NPM is the cause.

First published date

12/18/2018 11:14 PM

Last published date

8/22/2025 3:52 PM

Overview

Account gets locked out of AD

This is a very common issue. A customer calls in and says that his/her AD account gets locked out and they want to identify if NPM is the culprit.

Product section

Orion Platform

Cause

Customer's account is no longer in use or disabled from Active Directory

Resolution

  1. Check the database manager and query the Credentials table

 

 

 

Here you’ll see a list of account, find the account and check the credential owner column. On this example “administrator” is being used by APM which is SAM.

 

On a customer environment you’ll find a lot of names here. If the account is being used by the SolarWinds Platform you can find that in the Manage your credential field and change it there.

Settings > Credentials > Manage Window credentials

 

 

Now if it’s SAM, you’ll find it in the SAM credentials library on

SAM Settings > Global SAM Settings > Credential Library

 

 

You can also find it on Orion Report scheduler. Just edit the schedule and go through the advanced settings

 

 

Now, that you’ve searched every hiding place that those credentials might be in the SolarWinds Platform then, it may lead to an environmental issue with the customer. Meaning that the issue is on their end.

 

Notes:

 

Each module installed in NPM may or may not have credentials settings. UDT has one for example, just go through those pages but always reference it with the credential table.

You can also check these (2) reports which should show you Credentials being used by WMI Nodes (at the NPM level) and what's being used at the APM/SAM level

 

CREDENTIALS USED BY WMI NODES

https://thwack.solarwinds.com/docs/DOC-172320

CREDENTIALS USED BY APM COMPONENT MONITORS

https://thwack.solarwinds.com/docs/DOC-160488

 

To use these download the .OrionReport and then copy them into this path on your Orion/NPM Server

 

--> C:\Program Files (x86)\SolarWinds\Orion\Reports\

 

Then go back to your SolarWinds Platform Web Console > http://<orionservername>/Orion/Reports/Default.aspx

 

Then search for the word "Credentials" and you should find both:

CREDENTIALS USED BY WMI NODES

CREDENTIALS USED BY APM COMPONENT MONITORS

 

Then put a check mark next to the one you want to view and then click > VIEW REPORT

Your output should look like these:

 

 

  • Need to determine for any old remnants of admin accounts that are no longer being used; have it deleted permanently



Please note that Thwack is a community space where users may post any content as a suggestion or recommendations to you for your internal use. The information set forth herein may come from third-party websites or customers. SolarWinds is not liable for any downtime or any issue that may occur if you perform the following suggestions on the link provided. Your organization should internally review and assess to what extent, if any, such custom scripts or recommendations will be incorporated into your environment