<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Cisco ISE (Authentication failed: 24415 User authentication against Active Directory failed since user's account is locked out) in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/cisco-ise-authentication-failed-24415-user-authentication/m-p/2128885#M141316</link>
    <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have a setup ISE 1.1.1. Users are getting authenticate against AD. Everything is working fine except some users report disconnection. I see in the ISE that (Authentication failed: 24415 User authentication against Active Directory failed since user's account is locked out). Users are using Windows 7 OS.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Error is enclosed &amp;amp; here is the port configuration.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Port Configuration.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;interface GigabitEthernet0/2&lt;/P&gt;&lt;P&gt;switchport access vlan 120&lt;/P&gt;&lt;P&gt;switchport mode access&lt;/P&gt;&lt;P&gt;switchport voice vlan 121&lt;/P&gt;&lt;P&gt;authentication event fail action next-method&lt;/P&gt;&lt;P&gt;authentication event server dead action reinitialize vlan 120&lt;/P&gt;&lt;P&gt;authentication event server alive action reinitialize &lt;/P&gt;&lt;P&gt;authentication host-mode multi-auth&lt;/P&gt;&lt;P&gt;authentication order mab dot1x&lt;/P&gt;&lt;P&gt;authentication priority dot1x mab&lt;/P&gt;&lt;P&gt;authentication port-control auto&lt;/P&gt;&lt;P&gt;authentication periodic&lt;/P&gt;&lt;P&gt;authentication timer reauthenticate server&lt;/P&gt;&lt;P&gt;mab&lt;/P&gt;&lt;P&gt;dot1x pae authenticator&lt;/P&gt;&lt;P&gt;dot1x timeout tx-period 60&lt;/P&gt;&lt;P&gt;spanning-tree portfast&lt;/P&gt;&lt;P&gt;ip dhcp snooping limit rate 30&lt;SPAN id="mce_marker"&gt; &lt;/SPAN&gt;interface GigabitEthernet0/2&lt;BR /&gt;switchport access vlan 120&lt;BR /&gt;switchport mode access&lt;BR /&gt;switchport voice vlan 121&lt;BR /&gt;authentication event fail action next-method&lt;BR /&gt;authentication event server dead action reinitialize vlan 120&lt;BR /&gt;authentication event server alive action reinitialize &lt;BR /&gt;authentication host-mode multi-auth&lt;BR /&gt;authentication order mab dot1x&lt;BR /&gt;authentication priority dot1x mab&lt;BR /&gt;authentication port-control auto&lt;BR /&gt;authentication periodic&lt;BR /&gt;authentication timer reauthenticate server&lt;BR /&gt;mab&lt;BR /&gt;dot1x pae authenticator&lt;BR /&gt;dot1x timeout tx-period 60&lt;BR /&gt;spanning-tree portfast&lt;BR /&gt;ip dhcp snooping limit rate 30&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Please help.&lt;/P&gt;</description>
    <pubDate>Mon, 11 Mar 2019 02:58:59 GMT</pubDate>
    <dc:creator>Tabish Mirza</dc:creator>
    <dc:date>2019-03-11T02:58:59Z</dc:date>
    <item>
      <title>Cisco ISE (Authentication failed: 24415 User authentication against Active Directory failed since user's account is locked out)</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ise-authentication-failed-24415-user-authentication/m-p/2128885#M141316</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have a setup ISE 1.1.1. Users are getting authenticate against AD. Everything is working fine except some users report disconnection. I see in the ISE that (Authentication failed: 24415 User authentication against Active Directory failed since user's account is locked out). Users are using Windows 7 OS.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Error is enclosed &amp;amp; here is the port configuration.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Port Configuration.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;interface GigabitEthernet0/2&lt;/P&gt;&lt;P&gt;switchport access vlan 120&lt;/P&gt;&lt;P&gt;switchport mode access&lt;/P&gt;&lt;P&gt;switchport voice vlan 121&lt;/P&gt;&lt;P&gt;authentication event fail action next-method&lt;/P&gt;&lt;P&gt;authentication event server dead action reinitialize vlan 120&lt;/P&gt;&lt;P&gt;authentication event server alive action reinitialize &lt;/P&gt;&lt;P&gt;authentication host-mode multi-auth&lt;/P&gt;&lt;P&gt;authentication order mab dot1x&lt;/P&gt;&lt;P&gt;authentication priority dot1x mab&lt;/P&gt;&lt;P&gt;authentication port-control auto&lt;/P&gt;&lt;P&gt;authentication periodic&lt;/P&gt;&lt;P&gt;authentication timer reauthenticate server&lt;/P&gt;&lt;P&gt;mab&lt;/P&gt;&lt;P&gt;dot1x pae authenticator&lt;/P&gt;&lt;P&gt;dot1x timeout tx-period 60&lt;/P&gt;&lt;P&gt;spanning-tree portfast&lt;/P&gt;&lt;P&gt;ip dhcp snooping limit rate 30&lt;SPAN id="mce_marker"&gt; &lt;/SPAN&gt;interface GigabitEthernet0/2&lt;BR /&gt;switchport access vlan 120&lt;BR /&gt;switchport mode access&lt;BR /&gt;switchport voice vlan 121&lt;BR /&gt;authentication event fail action next-method&lt;BR /&gt;authentication event server dead action reinitialize vlan 120&lt;BR /&gt;authentication event server alive action reinitialize &lt;BR /&gt;authentication host-mode multi-auth&lt;BR /&gt;authentication order mab dot1x&lt;BR /&gt;authentication priority dot1x mab&lt;BR /&gt;authentication port-control auto&lt;BR /&gt;authentication periodic&lt;BR /&gt;authentication timer reauthenticate server&lt;BR /&gt;mab&lt;BR /&gt;dot1x pae authenticator&lt;BR /&gt;dot1x timeout tx-period 60&lt;BR /&gt;spanning-tree portfast&lt;BR /&gt;ip dhcp snooping limit rate 30&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Please help.&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 02:58:59 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ise-authentication-failed-24415-user-authentication/m-p/2128885#M141316</guid>
      <dc:creator>Tabish Mirza</dc:creator>
      <dc:date>2019-03-11T02:58:59Z</dc:date>
    </item>
    <item>
      <title>Cisco ISE (Authentication failed: 24415 User authentication agai</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ise-authentication-failed-24415-user-authentication/m-p/2128886#M141319</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Are all the users on the same switch experiencing this issue? You may want to doublecheck the shared secret.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Tarik Admani &lt;BR /&gt;*Please rate helpful posts*&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 17 Jan 2013 05:08:16 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ise-authentication-failed-24415-user-authentication/m-p/2128886#M141319</guid>
      <dc:creator>Tarik Admani</dc:creator>
      <dc:date>2013-01-17T05:08:16Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco ISE (Authentication failed: 24415 User authentication</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ise-authentication-failed-24415-user-authentication/m-p/2128887#M141321</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;No only subset of users getting this issue. Rest is working fine.&lt;BR /&gt;&lt;BR /&gt;Sent from Cisco Technical Support iPhone App&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 19 Jan 2013 05:03:43 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ise-authentication-failed-24415-user-authentication/m-p/2128887#M141321</guid>
      <dc:creator>Tabish Mirza</dc:creator>
      <dc:date>2013-01-19T05:03:43Z</dc:date>
    </item>
    <item>
      <title>Cisco ISE (Authentication failed: 24415 User authentication agai</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ise-authentication-failed-24415-user-authentication/m-p/2128888#M141322</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;PRE&gt;The error message means that Active Directory server Reject the authentication attempt 
as for some reasons the user account got locked.I guess, You should ask your AD Team to check in the AD
Event Logs why did the user account got locked.&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;Under Even Viewers, You can find it out&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;Regards&lt;BR /&gt;Minakshi (Do rate the helpful posts) &lt;BR /&gt;&lt;/PRE&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 21 Jan 2013 22:53:06 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ise-authentication-failed-24415-user-authentication/m-p/2128888#M141322</guid>
      <dc:creator>minkumar</dc:creator>
      <dc:date>2013-01-21T22:53:06Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco ISE (Authentication failed: 24415 User authentication agains</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ise-authentication-failed-24415-user-authentication/m-p/5317273#M597628</link>
      <description>&lt;P&gt;Verify that the DHCP scope has enough available IP addresses to lease.&lt;/P&gt;&lt;P&gt;I encountered an issue where Cisco ISE was showing the error:&lt;BR /&gt;"User authentication against Active Directory failed since user's account is locked out."&lt;BR /&gt;However, after checking in Active Directory, there were no events indicating the user account was actually locked.&lt;/P&gt;&lt;P&gt;The root cause turned out to be an exhausted DHCP IP pool. The DHCP server had no available IP addresses to assign.&lt;/P&gt;&lt;P&gt;Expanding the IP address range of the subnet resolved the issue.&lt;/P&gt;</description>
      <pubDate>Mon, 04 Aug 2025 16:50:40 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ise-authentication-failed-24415-user-authentication/m-p/5317273#M597628</guid>
      <dc:creator>josealmh</dc:creator>
      <dc:date>2025-08-04T16:50:40Z</dc:date>
    </item>
  </channel>
</rss>

