A Domain User Account Constantly Getting Locked Out
The event id 4740 needs to be enabled so it gets locked anytime a user is locked out.
A domain user account constantly getting locked out. Both the powershell and the gui tool need auditing turned before the domain controllers will log any useful information. This notification means the account is automatically temporarily blocked by the active directory domain security policy and can t be used to login to the domain computer. Select file select target. Using powershell to find the source of account lockouts.
Now you will see the account status across all domain controllers. The referenced account is currently locked out and may not be logged on to. Every account lockout is recorded there in the security event log. Not sure what your rights on the domain are but this link tells how to use it to search the event logs on the domain controller for account lockouts among other things.
One way to do this is by using the get addomain cmdlet. The first column will give you the domain controller names hidden in the example below. The pdc emulator is a central place that can be queried for all account lockout events. Within this event log we can see the resource computer the caller computer name is the resource computer name.
Note down the machine name and time at which event was generated. Before looking for an event id of 4740 we need to find the domain controller that holds the pdc emulator role. When an account is locked out a 4740 event is logged in the security log on the pdc of your domain. The user state will tell you whether the account is locked or not.
To find first once account is locked out go to primary domain controller of your domain and look for event id 644 in security log which will give the name of caller machine name. We just used this tool to find out which machine was locking out a user who was getting locked out several times a day and didn t know why. Go to domain controller pdc in the security log check whether we received the following event pdc event viewer windows logs security log 4740 a user account was locked out.