You are using an out of date browser. It may not display this or other websites correctly. You should upgrade or use an alternative browser.
event 4740
About this tag
Event 4740 in the Windows Security log indicates a user account was locked out. In a domain environment, this event records the account that was locked, the subject (typically the domain controller), and the caller computer name. The excerpt shows a scenario where domain admin accounts were locked out from specific PCs, leading to investigation for malware or misconfiguration. Troubleshooting event 4740 often involves identifying the source computer and reviewing logon attempts to determine the cause of repeated lockouts.
Hello,
we are facing an issue where the domain admin accounts are becoming locked randomly.
We have filtered out the event 4740 in the windows security log and we can see the PCs triggering this lockdown.
-------------------------------------
A user account was locked out.
Subject:
Security ID...
account lockout
antivirus
contoso
domain admin
domain issues
event4740
kerberos
malware
network analysis
network security
rdp sessions
security id
smb protocol
system admin
system format
troubleshooting
user account
user management
windows logs
windows security