Share via

Event Viewer showing account lockout alerts (4740) from computers which are not in my domain (Caller Computer is not in domain)

Samitha Weeraman 1 Reputation point
Nov 21, 2022, 12:56 AM

Hi guys,

This is one of those weird ones.

Recently came across few account lockouts (this includes the build in Administrator accounts as well) that have been happening in our domain, and these event alerts are showing computers which are not in our domain. Now there are few alerts where the "Caller Computer Name" is empty, but the majority shows up with computer names which are not in our domain. Any idea why the caller name is not in our domain? was thinking this could be an attack from the outside but looking at the firewall its highly unlikely.

I have already tried using netwrix and Microsoft Account Lockout tool to try and drill down the issue also was looking at Netlogon logs to see if any info will give a better understanding. But i still cannot have a break through at this issue. Below are some screen print to help you understand the issue.

Looking at the Netlogon, you can see the weird computer name request is coming via a device that is in the network. But the device name is not in our network. If anyone can point me in some direction that will be greatly appriciated. Could this be some 3rd party app in that computer generating this request?

Thanks Guys!

Event view log ID 4740 with Netlogon Logs.
262250-event-viewer-4740-netlogon.jpg

Netwrix Logs
262277-netwrix-results.jpg

Thanks guys,

Windows Server
Windows Server
A family of Microsoft server operating systems that support enterprise-level management, data storage, applications, and communications.
13,726 questions
{count} votes

Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.