Event ID 1210: Extranet lockout.
|Description||AD FS will write extranet lockout events to the security audit log:
|Category||Active directory Federation service|
Reasons to monitor this event:
- While in log only mode, you can check the security audit log for lockout events.
- For any events found, you can check the user state using the Get-ADFSAccountActivity cmdlet to determine if the lockout occurred from familiar or unfamiliar IP addresses, and to double check the list of familiar IP addresses for that user.
Event 1210 applies to the following operating systems:
- Windows Server 2008 R2 and 7
- Windows Server 2012 R2 and 8.1
- Windows Server 2016 and 10