How to display why the user account has been locked out in AD

Anonymous
2023-08-28T11:49:59+00:00

Hello

I have a issue with user locked out. That's happen to a multiple user's in AD. Maybe the windows credentials have been used in another but i do not know how to check that. If there is a powershell command that will be very helpful for me.

Thank you

Windows Server Identity and access Active Directory

Locked Question. This question was migrated from the Microsoft Support Community. You can vote on whether it's helpful, but you can't add comments or replies or follow the question. To protect privacy, user profiles for migrated questions are anonymized.

0 comments No comments
{count} votes

1 answer

Sort by: Most helpful
  1. Anonymous
    2023-08-29T02:21:11+00:00

    Hello M.U.F.C,

    Thank you for posting in Microsoft Community forum.

    Based on the description "I have a issue with user locked out. That's happen to a multiple user's in AD.", have you made any change before the user accounts locked out? For example, if you install any KB on any DC or on any domain-join machines? Or make any GPO setting related to Cipher suites or TLS/SSL?

    Based on the description "If there is a powershell command that will be very helpful for me.", I am afraid there is no, please troubleshot as below:

    1. Check if you can see multiple Event ID 4771 or 4776 via Security log on DC/PDC.
      2.Check if you can see Event ID 4740 via Security log on DC/PDC.
      3.If these user accounts are not locked out by the same change or the same cause, we may need to check one domain user account first.
      4.Find one locked account, and for this domain user account, if you can see Event ID 4771 or 4776 and Event ID 4740 related this domain account, can you see which machine lock the user account? If so, logon the machine locked out this account to try to check the reason. • Check Credential Management to see if the user's old credentials are cached (Control Panel) • Check whether the network disk is mounted with the wrong password • Check if the user started the service with the wrong password, run scheduled tasks, etc • Are there other third-party programs that cache incorrect passwords for users

    I hope the information above is helpful. If you have any question or concern, please feel free to let us know.

    Best Regards,
    Daisy Zhou

    0 comments No comments