AD Account lockout cause unknown

Ben Lan 181 Reputation points
2024-07-03T16:38:29.4066667+00:00

An account lockout event code 4740 (User account XXX was locked from computer T00050068-RGB01) has occurred on our network twice for non-essential AD accounts however I do need to find the cause for security purposes. The caller machine name is T00050068-RGB01 - is this a vendor specific id that rings a bell with anyone? Google search has nothing. The caller IP address is the same as the machine name - no IP address provided. How can the identity of the machine be determined as its not part of the domain?

Windows Server Security
Windows Server Security
Windows Server: A family of Microsoft server operating systems that support enterprise-level management, data storage, applications, and communications.Security: The precautions taken to guard against crime, attack, sabotage, espionage, or another threat.
1,848 questions
0 comments No comments
{count} votes

1 answer

Sort by: Most helpful
  1. Dillon Silzer 57,431 Reputation points
    2024-07-04T06:32:57.55+00:00

    Hi Ben,

    Something is triggering the account logout (most likely something is trying to login with an old credential). In the past, I have seen a person's machine/phone trying to use AD credentials to connect to WiFi (if you use Radius/NPS) to authenticate.

    If it isn't WiFi, then it is some application trying again and again with wrong/expired credentials.


    If this is helpful please accept as answer or upvote.

    Best regards,

    Dillon Silzer, Director | Cloudaen.com | Cloudaen Computing Solutions

    0 comments No comments

Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.