I have a customer who his admin account is being locked from AD very random. After checking all security logs, more specifically for 4740 events, we can identify the source of the locked accounts appears to be a domain controller in Azure. My client has a hybrid AD-Azure and Office 365- Exchange 2010.
Any ideas on why the 4740 event is logged in a DC in Azure? My client has closed all RDP sessions from the domain, and even the dc in Azure, but his admin account keeps being locked very random, and the source of the locked account is the 2 DCs in Azure
Any ideas on how to resolve this issue?
Please, provide instructions step by step to resolve the issues, and an explanation on why the DC in Azure seems to be the source of the locked account?