Back to all events4740AccountsWARNLast updated:
Account was locked out
What it means
The account exceeded the bad-password threshold. The event always lands on the PDC Emulator; Caller Computer Name points at the source.
When it is normal and when it is suspicious
Normal: a single lockout after a password change, usually a phone with the old password. Suspicious: repeated lockouts every few minutes at night from one host.
First steps
- 1Find 4740 on the PDC Emulator and read Caller Computer Name.
- 2On that machine look for 4771/4625 to see what keeps sending the old password.
- 3Usual suspects: a stale RDP session, a service with a saved password, a phone with mail, a mapped drive.
Fields worth checking
Related events
This reference is a starting point for investigation, not a replacement for your organisation's security policy.