Need to find out at what time and what machine a user account was locked out at

Posted on 2014-02-08
Medium Priority
Last Modified: 2014-03-29
Someone locked out a user account in Active Directory and I need to find out what time and from what machine it was locked out. I have already unlocked the account. I have a Server 2003 Domain Controller. Thanks in advance for the help.
Question by:schmida54017
LVL 23

Accepted Solution

Patrick Bogers earned 1500 total points
ID: 39844220
Put a filter on eventlog and look for Event 644 and 539

Expert Comment

ID: 39846580
"Account lockout tool" is the best option to find out "what time and from what machine" it was locked out. By this tool, You can get the complete information about the account lockout cause and status.
Further, if you wish to avoid such issues and get alert of all changes in AD, you can also check this software(http://www.activedirectoryaudit.com/) which would be a best practice and good choice for you.
LVL 26

Expert Comment

by:Leon Fester
ID: 39846675
There is a tool from Microsoft to speed up this process:
EventCombMT is a multithreaded tool that you can use to search the event logs of several different computers for specific events, all from one central location. You can configure EventCombMT to search the event logs in a very detailed fashion. The following are some of the search parameters that you can specify:•Individual event IDs
•Multiple event IDs
•A range of event IDs
•An event source
•Specific event text
•How many minutes, hours, or days back to scan
Some specific search categories are built-in, such as Account Lockouts. The Account Lockouts search is preconfigured to include event IDs 529, 644, 675, 676, and 681. Additionally, you can add event ID 12294 to search for potential attacks against the Administrator account.

Featured Post

Has Powershell sent you back into the Stone Age?

If managing Active Directory using Windows Powershell® is making you feel like you stepped back in time, you are not alone.  For nearly 20 years, AD admins around the world have used one tool for day-to-day AD management: Hyena. Discover why.

Question has a verified solution.

Are you are experiencing a similar issue? Get a personalized answer when you ask a related question.

Have a better answer? Share it in a comment.

Join & Write a Comment

It’s time for spooky stories and consuming way too much sugar, including the many treats we’ve whipped for you in the world of tech. Check it out!
I’m willing to make a bet that your organization stores sensitive data in your Windows File Servers; files and folders that you really don’t want making it into the wrong hands.
This Micro Tutorial hows how you can integrate  Mac OSX to a Windows Active Directory Domain. Apple has made it easy to allow users to bind their macs to a windows domain with relative ease. The following video show how to bind OSX Mavericks to …
Microsoft Active Directory, the widely used IT infrastructure, is known for its high risk of credential theft. The best way to test your Active Directory’s vulnerabilities to pass-the-ticket, pass-the-hash, privilege escalation, and malware attacks …

619 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question