Hello @Shariha Abdul Rahim ,
Thank you for posting here.
1.Based on the description, the account server\user123 you mentioned is one local account insted of domain account, is it right?
2.Can you see 4776 and 4740 or 4771 and 4740 on this server Security log/Windows Logs/Event Viewer?
3.Do you know on which machine the account is locked out? If so, on this machien, we can check the following information:
• Check the credential management to see if there is cached user’s old credentials (server\user123)?
• Check whether there is a wrong password of server\user123 to mount the network disk?
• Check whether the user has used the wrong password of server\user123 to start services, run scheduled tasks, etc.
• Are there other third-party programs that cache the user's wrong password of server\user123
• Check if there is any process using the wrong credential of server\user123
• And so on
Hope the information above is helpful. If you have any question or concern, please feel free to let us know.
Best Regards,
Daisy Zhou