Domain User Account Locked Out Frequently
Microsoft communicated as a known issue and they are working on it.
Domain user account locked out frequently. Find the domain controller with the pdc emulator role. Account lockout and management tool. Auditing is now turned on and event 4740 will be logged in the security events logs when an account is locked out. Usually unlocking their ad account from active directory users and computers will resolve the issue but user facing frequently account locking after unlocking the account.
The name of the computer from which the lock was made is specified in the caller computer name value. I haven t noticed any negative effects but as it s not the default i don t consider it a solution. I changed my domain account properties for the pre authentication as shown below. Server active directory.
However the user is not failing any attempts when he unlocks his system. If you have a single domain controller shame on you then you can skip to the next step hopefully you have at least two dcs. One on my users is being locked out of his active directory account on a daily basis. I ticked this option for the user account and it hasn t locked out since.
Check the event security log for event id 4740 a user account was locked out it will tell you the bad computer name on that the particular account is locking out. You will see a list of events of locking domain user accounts on this dc with an event message a user account was locked out find the last entry in the log containing the name of the desired user in the account name value. As a system administrator there will be times that user will be contacting you for unlocking their ad account when they get locked out. If you found the account is getting locked from a mobile device and unable to fix the by performing above steps take the necessary backup and wipe the device completely and reconfigure the device.
Once we identify the domain controller that is locking out the user account you can also check the locked account on pdc dc. In this case the computer name is lon dc01. This just started last week.