Skip to main content
AD Academy
Back to all events
4740Security (PDC Emulator)AccountsWARNLast updated:

Account was locked out

What it means

The account exceeded the bad-password threshold. The event always lands on the PDC Emulator; Caller Computer Name points at the source.

When it is normal and when it is suspicious

Normal: a single lockout after a password change, usually a phone with the old password. Suspicious: repeated lockouts every few minutes at night from one host.

First steps

  1. 1Find 4740 on the PDC Emulator and read Caller Computer Name.
  2. 2On that machine look for 4771/4625 to see what keeps sending the old password.
  3. 3Usual suspects: a stale RDP session, a service with a saved password, a phone with mail, a mapped drive.

Fields worth checking

FieldWhat to look at
TargetUserNameWho got locked. For a service account, hunt an old password in a service or scheduled task.
Caller Computer NameThe real source of the lockout. Sometimes blank — then look for 4771/4625 at the same time on the DC.

Related events

This reference is a starting point for investigation, not a replacement for your organisation's security policy.