Skip to main content
AD Academy
Back to all recipes
Level: JuniorLast updated:

Find what keeps locking a user's account

$pdc = (Get-ADDomain).PDCEmulator
Get-WinEvent -ComputerName $pdc -FilterHashtable @{LogName='Security';Id=4740} -MaxEvents 20 |
  Select-Object TimeCreated, @{n='User';e={$_.Properties[0].Value}},
                              @{n='Source';e={$_.Properties[1].Value}}

Why it works this way

Unlocking without finding the source means the same ticket in an hour.

Command breakdown

ParameterWhy it works this way
PDCEmulatorEvent 4740 is logged only on the PDC Emulator — searching another DC returns nothing.

Watch out

  • Source is the machine that sent the bad password.
  • Empty? Look for 4771 with code 0x18 at the same time.

Related events

Similar recipes