Domain Controller Administrator Account Locked Event ID

Sachin Shinde 1 Reputation point
2021-07-23T06:58:13.243+00:00

Hi,

We have Domain Controller & Additional Domain controller in our environment. From last few days false event ID 4740 getting generated continuously for every second for Domain controller Administrator ID. Administrator account is not getting locked but event ID 4740 getting generates in Security event. We have not used administrator account for any service.

117376-image.png

Thanks & Regards,
Sachin Shinde

Active Directory
Active Directory
A set of directory-based technologies included in Windows Server.
6,141 questions
{count} votes

8 answers

Sort by: Most helpful
  1. Sachin Shinde 1 Reputation point
    2021-07-29T05:51:32.553+00:00

    Hi,

    I have checked for 4625 event but not found single event for parrot ID. Also tried to run rundll32 keymgr.dll,KRShowKeyMgr command but got below result.

    118876-image.png

    Any other option to find running processes using same ID.

    Thanks,
    Sachin


  2. Sachin Shinde 1 Reputation point
    2021-07-29T11:04:52.317+00:00

    Hi,

    Thanks for response. In client address no IP is showing.

    119054-image.png

    Thanks,
    Sachin Shinde


  3. Sagarr 1 Reputation point
    2021-12-10T07:09:03.893+00:00

    @Hannah Xiong

    I'm also getting the same problem within a production environment and it is happening with several users and when I asked users about their account locked out, users have no answer for that like they haven't gotten any locked out prompt on their screen.

    I have searched for all the logs within that specific DC but didn't get any information about the origin of that log or any reason for the account being locked out.

    There is several DC configured in my environment but this is happening with only 3 DC.

    0 comments No comments