I'm at a loss here and don't know where to look next. Some background first. We have a 60+ user network with 12 Windows 2000 servers running everything from SQL, Exchange, Citrix, File/Print/Fax, plus many other services. All servers are hotfixed, patched, secured, running the latest antivirus signatures. We have 2 pipes to the internet with firewalls, intrusion detection, content filtering. We thought we should be pretty safe from average security problems.

This is where I'm at a loss. A few days ago we had some users complaining that their accounts were locked out after they logged in and were working for a while. We started examining the security logs and found there were no indication of anthing that would lock out a user for any reason. We audit everything down to the file level because we develop software. I have nothing to tell these users and can't think of anything else to do but keep unlocking their accounts. There are a bunch of strange logs that we can't explain. Some users seem to be randomly accessing other users profiles and getting blocked. This shows up in the logs but it would not cause an account to be locked out.

Nothing has been changed in our network recently. Any help or suggestions would be appreciated very much.

Thanks in advance.