event 4740

About this tag
Event 4740 in the Windows Security log indicates a user account was locked out. In a domain environment, this event records the account that was locked, the subject (typically the domain controller), and the caller computer name. The excerpt shows a scenario where domain admin accounts were locked out from specific PCs, leading to investigation for malware or misconfiguration. Troubleshooting event 4740 often involves identifying the source computer and reviewing logon attempts to determine the cause of repeated lockouts.
  1. V

    Domain admin account lockouts from domain pcs

    Hello, we are facing an issue where the domain admin accounts are becoming locked randomly. We have filtered out the event 4740 in the windows security log and we can see the PCs triggering this lockdown. ------------------------------------- A user account was locked out. Subject: Security ID...
Back
Top