I was wondering if it were possible to have a ADUC saved query that would
return all users who have 2 failed logon attempts.
I have 3 strikes set and a number of users have been locked out by
removing
a smart card from one system and locking it and then logging in to a
laptop.
So I was wondering if there was a way to pull this value to see if they
were
happening before of after logon. I am seeing alot of type 3 logon events
and
some type 11's. I know that I could parse the logs but I was simply hoping
for a broader view.
I have no experience with LDAP so any help would be appreciated.