Domain User Account Locked
Audit account lockout to audit success and failure.
Domain user account locked. Each day a particular user constantly get locked out of his computer. If you have a single domain controller shame on you then you can skip to the next step. Find the domain controller with the pdc emulator role. By now you should be able to quickly pinpoint all of the accounts that are currently locked out in your domain as well as see a history of all account lockouts.
Now it s time to have a stern talking to joe about leaving those rdp sessions open. The name of the computer from which the lock was made is specified in the caller computer name value. To unlock a user s account find ad user object open the properties go to the account tab check unlock account this account is currently locked out on this active directory domain controller and press ok. It seems the lockouttime flag is still greater than one in this instance despite the user account not being locked.
I believe he has a session somewhere on another machine where we need to log him out. We always need to unlock his domain account to allow him to log in. In the user properties dialog box select the account tab and uncheck the account is locked out check box. Audit user account management success and failure.
This seems to then put that flag back to 0. You will see a list of events of locking domain user accounts on this dc with an event message a user account was locked out find the last entry in the log containing the name of the desired user in the account name value. Enable success and failure for the audit user account management policy. I use a lockout tool to trace the source.
In this case the computer name is lon dc01. This happened after he changed his domain password. When an account is locked out a 4740 event is logged in the security log on the pdc of your domain. You can clear and remove these from the query view by ticking the unlock account option in the user properties even though the account isn t locked.