About this tag
Event 4740 in the Windows Security log indicates a user account was locked out. In a domain environment, this event records the account that was locked, the subject (typically the domain controller), and the caller computer name. The excerpt shows a scenario where domain admin accounts were locked out from specific PCs, leading to investigation for malware or misconfiguration. Troubleshooting event 4740 often involves identifying the source computer and reviewing logon attempts to determine the cause of repeated lockouts.
-
V
Domain admin account lockouts from domain pcs
Hello, we are facing an issue where the domain admin accounts are becoming locked randomly. We have filtered out the event 4740 in the windows security log and we can see the PCs triggering this lockdown. ------------------------------------- A user account was locked out. Subject: Security ID...- v0id
- Thread
- account lockout antivirus contoso domain admin domain issues event 4740 kerberos malware network analysis network security rdp sessions security id smb protocol system admin system format troubleshooting user account user management windows logs windows security
- Replies: 1
- Forum: Windows Server Forums