User lock outs - Audit failures on Secuirty log

Tim Trotter 1 Reputation point
2022-08-22T17:58:31.263+00:00

Hello,

Several users at my job are getting locked out of their account due to too many login attempts even though they are claiming to have not attempted to log in for hours.

The security log shows an 'audit failure' with the device listed as our domain controller.

I've also gotten this with Kerberos listed as the device name.

Does anyone know if a service can be causing this? Or should I be more concerned about a brute force attempt?

Thank you

Active Directory
Active Directory
A set of directory-based technologies included in Windows Server.
6,244 questions
{count} votes

1 answer

Sort by: Most helpful
  1. Gary Reynolds 9,406 Reputation points
    2022-08-23T09:59:37.837+00:00

    Hi @Tim Trotter

    Have a look at this article, it might help identify why the accounts are being locked out.

    https://nettools.net/troubleshoot-account-lockouts/

    Gary.

    0 comments No comments