Support
 
Phone Get Quote
 
Support
 
US: +1 888 720 9500
US: +1 888 791 1189
Intl: +1 925 924 9500
Aus: +1 800 631 268
UK: 0800 028 6590
CN: +86 400 660 8680

Direct Inward Dialing: +1 408 916 9892

 

How to find what's locking out
an Active Directory account

Start your free trial

Active Directory (AD) users getting locked out of their accounts is a common issue that sysadmins have to resolve almost every day. A smart way to handle this issue is to identify the source of these lockouts and rectify the root cause. However, this is both exhausting and time-consuming when you have to deal with a large number of locked-out users and have to find the source of each lockout. Below, you'll learn how to find what's locking out an AD account.

Find what's locking out an AD account using native auditing

Steps to enable auditing using the GPMC

Perform the following actions on the domain controller (DC):

  1. Open the Start menu. Search for and open the Group Policy Management Console (GPMC). You can also run the command gpmc.msc.
How to find what's locking out an Active Directory account
  1. Right-click the domain or organizational unit (OU) where you want to audit account lockouts, and click Create a GPO in this domain, and Link it here.

Note: If you have already created a GPO, click Link an Existing GPO.

How to find what's locking out an Active Directory account
  1. Name the GPO.
  2. Right-click the GPO and choose Edit.
How to find what's locking out an Active Directory account
  1. In the left pane of the Group Policy Management Editor, navigate to Computer Configuration > Policies > Windows Settings > Security Settings > Advanced Audit Policy Configuration > Audit Policies > Account Management.
How to find what's locking out an Active Directory account
  1. In the right pane, you will see the list of policies under Account Management. Double-click Audit User Account Management and check the boxes labeled Configure the following audit events, Success, and Failure.
How to find what's locking out an Active Directory account
  1. Click Apply and then OK.
  2. Go back to the Group Policy Management Console. In the left pane, right-click the domain or OU that the GPO was linked to and click Group Policy Update. This step makes sure the new Group Policy settings are applied instantly instead of waiting for the next scheduled refresh.
How to find what's locking out an Active Directory account

Steps to view the logged events in the Event Viewer

Once the above steps are complete, events will be logged in the event log. These can be viewed in the Event Viewer by following the steps below:

  1. Open the Start menu, search for Event Viewer, and click to open it.
  2. In the left pane of the Event Viewer window, navigate to Windows Logs > Security. Here, you will find a list of all the security events that are logged in the system.
How to find what's locking out an Active Directory account
  1. In the right pane under Security, click Filter Current Log.
How to find what's locking out an Active Directory account
  1. In the pop-up window, enter 4740 in the field labeled <All Event IDs>.
  2. Click OK. This will provide a list of occurrences of the Event ID you entered.
  3. Double-click the Event ID to view its properties (description).
How to find what's locking out an Active Directory account

In the event description, the Caller Computer Name is shown.

To perform a more detailed analysis of the cause of this lockout, carry out the following actions on the DC:

  1. In the Event Viewer, filter the current view to look for the Event ID 4625, which is logged when there is a failed logon.
How to find what's locking out an Active Directory account
  1. On the right pane of the Event Viewer window, click Find, enter the name of the user that was locked out, and click Find Next.
How to find what's locking out an Active Directory account
  1. Look for an event that was logged after the account lockout time and view its properties.
How to find what's locking out an Active Directory account
  1. Scroll down to Caller Process Name. This will show you the location of the process that possibly caused the lockout.

In the above case, the account lockout was called by the process java.exe.

This process requires a lot of effort even for just one end user. To perform this analysis on a large number of end users would be time-consuming, impractical, and ineffective.

With ADAudit Plus, you can perform a thorough analysis of all possible sources of the lockout in just a click using the built-in Account Lockout Analyzer.

Find what's locking out AD accounts using ManageEngine ADAudit Plus

Once the audit policies mentioned in the previous section are enabled, follow these steps:

  1. Download and install ADAudit Plus.
  2. Find the steps to configure auditing on your domain controller here.
  3. Open the console and navigate to Reports > Active Directory > User Management > Account Lockout Analyzer.

This will show you a detailed report of locked out accounts sorted by time.

How to find what's locking out an Active Directory account

Click on Details under the Analyzer Details column to see the possible reasons behind each account lockout.

1
 

Analyze various components that could be causing the lockout with the account lockout analyzer.

2
 

Old cached credentials being used by Windows services, scheduled tasks, or other components might be causing these lockouts.

How to find what's locking out an Active Directory account

Analyze various components that could be causing the lockout with the account lockout analyzer.
Old cached credentials being used by Windows services, scheduled tasks, or other components might be causing these lockouts.

Advantages of ADAudit Plus over native auditing

  • View reports on all changes to AD objects, ensuring a foolproof audit trail.
  • Get instant alerts for unusual user activity and automate responses to these alerts with its built in user behavior analytics engine.
  • Prove compliance with IT regulations like SOX, HIPAA, GLBA, PCI DSS, FISMA, and the GDPR using out-of-the-box compliance reports.

ADAudit Plus Trusted By