This article will guide you on steps to find the source of Account Lockouts in the Active Directory #domain.
The most common underlying cause for #AD account lockouts, beyond users forgetting their password, is a running application or background service on a device that is authenticating with stale credentials.
To Track Source of Account Lockouts in #Active #Directory:
1. Search for the #DC (Domain Controller) having the PDC Emulator Role.
2. Look for the Event ID 4740.
3. Put Appropriate Filters in Place.
4. Find Out the Locked Out Account Event Whose Information is Require.
5. Open the #Event Report, to Find the Source of the Locked Out account.